GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-03-10 17:34:19
Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e WDC_WD2500JS-00NCB1 rev.10.02E02
Running: bnih5s0s.exe; Driver: C:\DOCUME~1\Gr2eg0rz\USTAWI~1\Temp\pxtdapow.sys


---- System - GMER 1.0.15 ----

SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwAddBootEntry [0xB0DB4DC4]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                                             ZwAllocateVirtualMemory [0xB0E41904]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwAssignProcessToJobObject [0xB0DB5832]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwClose [0xB0DE1ABD]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwCreateEvent [0xB0DBA25C]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwCreateEventPair [0xB0DBA2A8]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwCreateIoCompletion [0xB0DBA39A]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwCreateKey [0xB0DE1471]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwCreateMutant [0xB0DBA1CA]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwCreateSection [0xB0DBA2EC]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwCreateSemaphore [0xB0DBA212]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwCreateTimer [0xB0DBA354]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwDeleteBootEntry [0xB0DB4E10]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwDeleteKey [0xB0DE2183]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwDeleteValueKey [0xB0DE2439]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwDuplicateObject [0xB0DB7920]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwEnumerateKey [0xB0DE1FEE]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwEnumerateValueKey [0xB0DE1E59]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                                             ZwFreeVirtualMemory [0xB0E419DE]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwLoadDriver [0xB0DB4AA2]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwModifyBootEntry [0xB0DB4E5C]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwNotifyChangeKey [0xB0DB7C94]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwNotifyChangeMultipleKeys [0xB0DB5AD6]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwOpenEvent [0xB0DBA286]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwOpenEventPair [0xB0DBA2CA]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwOpenIoCompletion [0xB0DBA3BE]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwOpenKey [0xB0DE17CD]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwOpenMutant [0xB0DBA1F0]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwOpenProcess [0xB0DB7490]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwOpenSection [0xB0DBA326]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwOpenSemaphore [0xB0DBA23A]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwOpenThread [0xB0DB76C4]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwOpenTimer [0xB0DBA378]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                                             ZwProtectVirtualMemory [0xB0E41B4A]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwQueryKey [0xB0DE1CD4]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwQueryObject [0xB0DB59A2]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwQueryValueKey [0xB0DE1B26]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                                             ZwRenameKey [0xB0E4B858]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwRestoreKey [0xB0DE0AE4]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwSetBootEntryOrder [0xB0DB4EA8]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwSetBootOptions [0xB0DB4EF4]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwSetSystemInformation [0xB0DB4B12]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwSetSystemPowerState [0xB0DB4CB6]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwSetValueKey [0xB0DE228A]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwShutdownSystem [0xB0DB4C5E]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwSystemDebugControl [0xB0DB4D26]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                                             ZwTerminateProcess [0xB0E41C0A]
SSDT            \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)                                                                                             ZwVdmControl [0xB0DB4F40]
SSDT            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                                             ZwWriteVirtualMemory [0xB0E41A8A]

Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                                             ZwCreateProcessEx [0xB0E57A72]
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                                             ObInsertObject
Code            \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)                                                                                             ObMakeTemporaryObject

---- Kernel code sections - GMER 1.0.15 ----

PAGE            TUKERNEL.EXE!ObInsertObject                                                                                                                                                       8056DA64 5 Bytes  JMP B0E5642C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE            TUKERNEL.EXE!PsCreateSystemThread + 455                                                                                                                                           805766FB 4 Bytes  CALL B0DB6173 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
PAGE            TUKERNEL.EXE!SeQueryInformationToken + A0C                                                                                                                                        8058B9EC 7 Bytes  JMP B0E57A76 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
PAGE            TUKERNEL.EXE!ObMakeTemporaryObject                                                                                                                                                805AD1E0 5 Bytes  JMP B0E5496C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software)
.text           C:\WINDOWS\system32\DRIVERS\nv4_mini.sys                                                                                                                                          section is writeable [0xB6903380, 0x8D6CD5, 0xE8000020]
.text           win32k.sys!EngFreeUserMem + 674                                                                                                                                                   BF80992D 5 Bytes  JMP B0DB90F8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngFreeUserMem + 35D0                                                                                                                                                  BF80C889 5 Bytes  JMP B0DB8FF4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngDeleteSurface + 45                                                                                                                                                  BF813921 5 Bytes  JMP B0DB8FAE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!BRUSHOBJ_pvAllocRbrush + 11F0                                                                                                                                          BF81C764 5 Bytes  JMP B0DB869C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngSetLastError + 79A8                                                                                                                                                 BF8242D4 5 Bytes  JMP B0DB7EFC \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngCreateBitmap + F9C                                                                                                                                                  BF828C3E 5 Bytes  JMP B0DB9262 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngUnmapFontFileFD + 2C50                                                                                                                                              BF831689 5 Bytes  JMP B0DB946A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngUnmapFontFileFD + B68E                                                                                                                                              BF83A0C7 5 Bytes  JMP B0DB8EB4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!FONTOBJ_pxoGetXform + C2CF                                                                                                                                             BF85198B 5 Bytes  JMP B0DB7DDE \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!XLATEOBJ_iXlate + F17                                                                                                                                                  BF85BEAA 5 Bytes  JMP B0DB875E \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!XLATEOBJ_iXlate + 3581                                                                                                                                                 BF85E514 5 Bytes  JMP B0DB82FC \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!XLATEOBJ_iXlate + 360C                                                                                                                                                 BF85E59F 5 Bytes  JMP B0DB84DA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngCreatePalette + 88                                                                                                                                                  BF85F812 5 Bytes  JMP B0DB7DC6 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngCreatePalette + 5457                                                                                                                                                BF864BE1 5 Bytes  JMP B0DB9032 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngGetCurrentCodePage + 4128                                                                                                                                           BF873F30 5 Bytes  JMP B0DB8494 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngGetLastError + 1606                                                                                                                                                 BF8911E2 5 Bytes  JMP B0DB8776 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngGradientFill + 26EE                                                                                                                                                 BF89478D 5 Bytes  JMP B0DB91AA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngStretchBltROP + 583                                                                                                                                                 BF895265 5 Bytes  JMP B0DB93C8 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngCopyBits + 3857                                                                                                                                                     BF89C60B 5 Bytes  JMP B0DB8684 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngCopyBits + 4DEC                                                                                                                                                     BF89DBA0 5 Bytes  JMP B0DB7F6C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngEraseSurface + A9F7                                                                                                                                                 BF8C2130 5 Bytes  JMP B0DB807C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngFillPath + 1517                                                                                                                                                     BF8CA592 5 Bytes  JMP B0DB8124 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngFillPath + 1797                                                                                                                                                     BF8CA812 5 Bytes  JMP B0DB825C \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngDeleteSemaphore + 3B3E                                                                                                                                              BF8EC297 5 Bytes  JMP B0DB7CCA \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngDeleteSemaphore + CB3F                                                                                                                                              BF8F5298 5 Bytes  JMP B0DB86B4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngCreateClip + 19DF                                                                                                                                                   BF91348A 5 Bytes  JMP B0DB7E9A \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngCreateClip + 25B3                                                                                                                                                   BF91405E 5 Bytes  JMP B0DB8028 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngCreateClip + 4F2C                                                                                                                                                   BF9169D7 5 Bytes  JMP B0DB85F4 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           win32k.sys!EngPlgBlt + 18FC                                                                                                                                                       BF946449 5 Bytes  JMP B0DB9320 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software)
.text           C:\WINDOWS\system32\DRIVERS\atksgt.sys                                                                                                                                            section is writeable [0xAFA1D300, 0x3AF78, 0xE8000020]
.text           C:\WINDOWS\system32\DRIVERS\lirsgt.sys                                                                                                                                            section is writeable [0xB09F4300, 0x1BCE, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text           C:\WINDOWS\system32\nvsvc32.exe[144] ntdll.dll!LdrLoadDll                                                                                                                         7C91632D 5 Bytes  JMP 001501F8 
.text           C:\WINDOWS\system32\nvsvc32.exe[144] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                           7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\nvsvc32.exe[144] ntdll.dll!LdrUnloadDll                                                                                                                       7C9171CD 5 Bytes  JMP 001503FC 
.text           C:\WINDOWS\system32\nvsvc32.exe[144] kernel32.dll!GetBinaryTypeW + 80                                                                                                             7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\nvsvc32.exe[144] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                        77E26D81 5 Bytes  JMP 003E1014 
.text           C:\WINDOWS\system32\nvsvc32.exe[144] ADVAPI32.dll!ChangeServiceConfigA                                                                                                            77E26E69 5 Bytes  JMP 003E0804 
.text           C:\WINDOWS\system32\nvsvc32.exe[144] ADVAPI32.dll!ChangeServiceConfigW                                                                                                            77E27001 5 Bytes  JMP 003E0A08 
.text           C:\WINDOWS\system32\nvsvc32.exe[144] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                           77E27101 5 Bytes  JMP 003E0C0C 
.text           C:\WINDOWS\system32\nvsvc32.exe[144] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                           77E27189 5 Bytes  JMP 003E0E10 
.text           C:\WINDOWS\system32\nvsvc32.exe[144] ADVAPI32.dll!CreateServiceA                                                                                                                  77E27211 5 Bytes  JMP 003E01F8 
.text           C:\WINDOWS\system32\nvsvc32.exe[144] ADVAPI32.dll!CreateServiceW                                                                                                                  77E273A9 5 Bytes  JMP 003E03FC 
.text           C:\WINDOWS\system32\nvsvc32.exe[144] ADVAPI32.dll!DeleteService                                                                                                                   77E274B1 5 Bytes  JMP 003E0600 
.text           C:\WINDOWS\system32\nvsvc32.exe[144] USER32.dll!SetWindowsHookExW                                                                                                                 7E37820F 5 Bytes  JMP 003F0804 
.text           C:\WINDOWS\system32\nvsvc32.exe[144] USER32.dll!UnhookWindowsHookEx                                                                                                               7E37D5F3 5 Bytes  JMP 003F0A08 
.text           C:\WINDOWS\system32\nvsvc32.exe[144] USER32.dll!SetWindowsHookExA                                                                                                                 7E381211 5 Bytes  JMP 003F0600 
.text           C:\WINDOWS\system32\nvsvc32.exe[144] USER32.dll!SetWinEventHook                                                                                                                   7E3817F7 5 Bytes  JMP 003F01F8 
.text           C:\WINDOWS\system32\nvsvc32.exe[144] USER32.dll!UnhookWinEvent                                                                                                                    7E3818AC 5 Bytes  JMP 003F03FC 
.text           C:\Program Files\AVAST Software\Avast\avastUI.exe[152] ntdll.dll!RtlDosSearchPath_U + 186                                                                                         7C916865 1 Byte  [62]
.text           C:\Program Files\AVAST Software\Avast\avastUI.exe[152] kernel32.dll!GetBinaryTypeW + 80                                                                                           7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\HPZipm12.exe[208] ntdll.dll!LdrLoadDll                                                                                                                        7C91632D 5 Bytes  JMP 001401F8 
.text           C:\WINDOWS\system32\HPZipm12.exe[208] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                          7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\HPZipm12.exe[208] ntdll.dll!LdrUnloadDll                                                                                                                      7C9171CD 5 Bytes  JMP 001403FC 
.text           C:\WINDOWS\system32\HPZipm12.exe[208] kernel32.dll!GetBinaryTypeW + 80                                                                                                            7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\HPZipm12.exe[208] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                       77E26D81 5 Bytes  JMP 003D1014 
.text           C:\WINDOWS\system32\HPZipm12.exe[208] ADVAPI32.dll!ChangeServiceConfigA                                                                                                           77E26E69 5 Bytes  JMP 003D0804 
.text           C:\WINDOWS\system32\HPZipm12.exe[208] ADVAPI32.dll!ChangeServiceConfigW                                                                                                           77E27001 5 Bytes  JMP 003D0A08 
.text           C:\WINDOWS\system32\HPZipm12.exe[208] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                          77E27101 5 Bytes  JMP 003D0C0C 
.text           C:\WINDOWS\system32\HPZipm12.exe[208] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                          77E27189 5 Bytes  JMP 003D0E10 
.text           C:\WINDOWS\system32\HPZipm12.exe[208] ADVAPI32.dll!CreateServiceA                                                                                                                 77E27211 5 Bytes  JMP 003D01F8 
.text           C:\WINDOWS\system32\HPZipm12.exe[208] ADVAPI32.dll!CreateServiceW                                                                                                                 77E273A9 5 Bytes  JMP 003D03FC 
.text           C:\WINDOWS\system32\HPZipm12.exe[208] ADVAPI32.dll!DeleteService                                                                                                                  77E274B1 5 Bytes  JMP 003D0600 
.text           C:\WINDOWS\system32\HPZipm12.exe[208] USER32.dll!SetWindowsHookExW                                                                                                                7E37820F 5 Bytes  JMP 003E0804 
.text           C:\WINDOWS\system32\HPZipm12.exe[208] USER32.dll!UnhookWindowsHookEx                                                                                                              7E37D5F3 5 Bytes  JMP 003E0A08 
.text           C:\WINDOWS\system32\HPZipm12.exe[208] USER32.dll!SetWindowsHookExA                                                                                                                7E381211 5 Bytes  JMP 003E0600 
.text           C:\WINDOWS\system32\HPZipm12.exe[208] USER32.dll!SetWinEventHook                                                                                                                  7E3817F7 5 Bytes  JMP 003E01F8 
.text           C:\WINDOWS\system32\HPZipm12.exe[208] USER32.dll!UnhookWinEvent                                                                                                                   7E3818AC 5 Bytes  JMP 003E03FC 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] ntdll.dll!LdrLoadDll                                                                                                                        7C91632D 5 Bytes  JMP 001401F8 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                          7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] ntdll.dll!LdrUnloadDll                                                                                                                      7C9171CD 5 Bytes  JMP 001403FC 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] kernel32.dll!GetBinaryTypeW + 80                                                                                                            7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] USER32.dll!SetWindowsHookExW                                                                                                                7E37820F 5 Bytes  JMP 003D0804 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] USER32.dll!UnhookWindowsHookEx                                                                                                              7E37D5F3 5 Bytes  JMP 003D0A08 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] USER32.dll!SetWindowsHookExA                                                                                                                7E381211 5 Bytes  JMP 003D0600 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] USER32.dll!SetWinEventHook                                                                                                                  7E3817F7 5 Bytes  JMP 003D01F8 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] USER32.dll!UnhookWinEvent                                                                                                                   7E3818AC 5 Bytes  JMP 003D03FC 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                       77E26D81 5 Bytes  JMP 003E1014 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] ADVAPI32.dll!ChangeServiceConfigA                                                                                                           77E26E69 5 Bytes  JMP 003E0804 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] ADVAPI32.dll!ChangeServiceConfigW                                                                                                           77E27001 5 Bytes  JMP 003E0A08 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                          77E27101 5 Bytes  JMP 003E0C0C 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                          77E27189 5 Bytes  JMP 003E0E10 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] ADVAPI32.dll!CreateServiceA                                                                                                                 77E27211 5 Bytes  JMP 003E01F8 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] ADVAPI32.dll!CreateServiceW                                                                                                                 77E273A9 5 Bytes  JMP 003E03FC 
.text           C:\WINDOWS\system32\PnkBstrA.exe[224] ADVAPI32.dll!DeleteService                                                                                                                  77E274B1 5 Bytes  JMP 003E0600 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] ntdll.dll!LdrLoadDll                                                                                                                        7C91632D 5 Bytes  JMP 001401F8 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                          7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] ntdll.dll!LdrUnloadDll                                                                                                                      7C9171CD 5 Bytes  JMP 001403FC 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] kernel32.dll!GetBinaryTypeW + 80                                                                                                            7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] USER32.dll!SetWindowsHookExW                                                                                                                7E37820F 5 Bytes  JMP 003D0804 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] USER32.dll!UnhookWindowsHookEx                                                                                                              7E37D5F3 5 Bytes  JMP 003D0A08 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] USER32.dll!SetWindowsHookExA                                                                                                                7E381211 5 Bytes  JMP 003D0600 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] USER32.dll!SetWinEventHook                                                                                                                  7E3817F7 5 Bytes  JMP 003D01F8 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] USER32.dll!UnhookWinEvent                                                                                                                   7E3818AC 5 Bytes  JMP 003D03FC 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                       77E26D81 5 Bytes  JMP 003E1014 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] ADVAPI32.dll!ChangeServiceConfigA                                                                                                           77E26E69 5 Bytes  JMP 003E0804 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] ADVAPI32.dll!ChangeServiceConfigW                                                                                                           77E27001 5 Bytes  JMP 003E0A08 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                          77E27101 5 Bytes  JMP 003E0C0C 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                          77E27189 5 Bytes  JMP 003E0E10 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] ADVAPI32.dll!CreateServiceA                                                                                                                 77E27211 5 Bytes  JMP 003E01F8 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] ADVAPI32.dll!CreateServiceW                                                                                                                 77E273A9 5 Bytes  JMP 003E03FC 
.text           C:\WINDOWS\system32\PnkBstrB.exe[236] ADVAPI32.dll!DeleteService                                                                                                                  77E274B1 5 Bytes  JMP 003E0600 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] ntdll.dll!LdrLoadDll                                                                                     7C91632D 5 Bytes  JMP 001501F8 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] ntdll.dll!RtlDosSearchPath_U + 186                                                                       7C916865 1 Byte  [62]
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] ntdll.dll!LdrUnloadDll                                                                                   7C9171CD 5 Bytes  JMP 001503FC 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] kernel32.dll!GetBinaryTypeW + 80                                                                         7C868D8C 1 Byte  [62]
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] USER32.dll!SetWindowsHookExW                                                                             7E37820F 5 Bytes  JMP 003E0804 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] USER32.dll!UnhookWindowsHookEx                                                                           7E37D5F3 5 Bytes  JMP 003E0A08 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] USER32.dll!SetWindowsHookExA                                                                             7E381211 5 Bytes  JMP 003E0600 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] USER32.dll!SetWinEventHook                                                                               7E3817F7 5 Bytes  JMP 003E01F8 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] USER32.dll!UnhookWinEvent                                                                                7E3818AC 5 Bytes  JMP 003E03FC 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] ADVAPI32.dll!SetServiceObjectSecurity                                                                    77E26D81 5 Bytes  JMP 003F1014 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] ADVAPI32.dll!ChangeServiceConfigA                                                                        77E26E69 5 Bytes  JMP 003F0804 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] ADVAPI32.dll!ChangeServiceConfigW                                                                        77E27001 5 Bytes  JMP 003F0A08 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] ADVAPI32.dll!ChangeServiceConfig2A                                                                       77E27101 5 Bytes  JMP 003F0C0C 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] ADVAPI32.dll!ChangeServiceConfig2W                                                                       77E27189 5 Bytes  JMP 003F0E10 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] ADVAPI32.dll!CreateServiceA                                                                              77E27211 5 Bytes  JMP 003F01F8 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] ADVAPI32.dll!CreateServiceW                                                                              77E273A9 5 Bytes  JMP 003F03FC 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe[360] ADVAPI32.dll!DeleteService                                                                               77E274B1 5 Bytes  JMP 003F0600 
.text           C:\WINDOWS\RTHDCPL.EXE[384] ntdll.dll!LdrLoadDll                                                                                                                                  7C91632D 5 Bytes  JMP 001401F8 
.text           C:\WINDOWS\RTHDCPL.EXE[384] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                                    7C916865 1 Byte  [62]
.text           C:\WINDOWS\RTHDCPL.EXE[384] ntdll.dll!LdrUnloadDll                                                                                                                                7C9171CD 5 Bytes  JMP 001403FC 
.text           C:\WINDOWS\RTHDCPL.EXE[384] kernel32.dll!GetBinaryTypeW + 80                                                                                                                      7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\RTHDCPL.EXE[384] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                                 77E26D81 5 Bytes  JMP 003D1014 
.text           C:\WINDOWS\RTHDCPL.EXE[384] ADVAPI32.dll!ChangeServiceConfigA                                                                                                                     77E26E69 5 Bytes  JMP 003D0804 
.text           C:\WINDOWS\RTHDCPL.EXE[384] ADVAPI32.dll!ChangeServiceConfigW                                                                                                                     77E27001 5 Bytes  JMP 003D0A08 
.text           C:\WINDOWS\RTHDCPL.EXE[384] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                                    77E27101 5 Bytes  JMP 003D0C0C 
.text           C:\WINDOWS\RTHDCPL.EXE[384] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                                    77E27189 5 Bytes  JMP 003D0E10 
.text           C:\WINDOWS\RTHDCPL.EXE[384] ADVAPI32.dll!CreateServiceA                                                                                                                           77E27211 5 Bytes  JMP 003D01F8 
.text           C:\WINDOWS\RTHDCPL.EXE[384] ADVAPI32.dll!CreateServiceW                                                                                                                           77E273A9 5 Bytes  JMP 003D03FC 
.text           C:\WINDOWS\RTHDCPL.EXE[384] ADVAPI32.dll!DeleteService                                                                                                                            77E274B1 5 Bytes  JMP 003D0600 
.text           C:\WINDOWS\RTHDCPL.EXE[384] USER32.dll!SetWindowsHookExW                                                                                                                          7E37820F 5 Bytes  JMP 003E0804 
.text           C:\WINDOWS\RTHDCPL.EXE[384] USER32.dll!UnhookWindowsHookEx                                                                                                                        7E37D5F3 5 Bytes  JMP 003E0A08 
.text           C:\WINDOWS\RTHDCPL.EXE[384] USER32.dll!SetWindowsHookExA                                                                                                                          7E381211 5 Bytes  JMP 003E0600 
.text           C:\WINDOWS\RTHDCPL.EXE[384] USER32.dll!SetWinEventHook                                                                                                                            7E3817F7 5 Bytes  JMP 003E01F8 
.text           C:\WINDOWS\RTHDCPL.EXE[384] USER32.dll!UnhookWinEvent                                                                                                                             7E3818AC 5 Bytes  JMP 003E03FC 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] ntdll.dll!LdrLoadDll                                                                                 7C91632D 5 Bytes  JMP 000801F8 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] ntdll.dll!RtlDosSearchPath_U + 186                                                                   7C916865 1 Byte  [62]
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] ntdll.dll!LdrUnloadDll                                                                               7C9171CD 5 Bytes  JMP 000803FC 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] kernel32.dll!GetBinaryTypeW + 80                                                                     7C868D8C 1 Byte  [62]
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] ADVAPI32.dll!SetServiceObjectSecurity                                                                77E26D81 5 Bytes  JMP 00311014 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] ADVAPI32.dll!ChangeServiceConfigA                                                                    77E26E69 5 Bytes  JMP 00310804 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] ADVAPI32.dll!ChangeServiceConfigW                                                                    77E27001 5 Bytes  JMP 00310A08 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] ADVAPI32.dll!ChangeServiceConfig2A                                                                   77E27101 5 Bytes  JMP 00310C0C 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] ADVAPI32.dll!ChangeServiceConfig2W                                                                   77E27189 5 Bytes  JMP 00310E10 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] ADVAPI32.dll!CreateServiceA                                                                          77E27211 5 Bytes  JMP 003101F8 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] ADVAPI32.dll!CreateServiceW                                                                          77E273A9 5 Bytes  JMP 003103FC 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] ADVAPI32.dll!DeleteService                                                                           77E274B1 5 Bytes  JMP 00310600 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] USER32.dll!SetWindowsHookExW                                                                         7E37820F 5 Bytes  JMP 00320804 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] USER32.dll!UnhookWindowsHookEx                                                                       7E37D5F3 5 Bytes  JMP 00320A08 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] USER32.dll!SetWindowsHookExA                                                                         7E381211 5 Bytes  JMP 00320600 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] USER32.dll!SetWinEventHook                                                                           7E3817F7 5 Bytes  JMP 003201F8 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[452] USER32.dll!UnhookWinEvent                                                                            7E3818AC 5 Bytes  JMP 003203FC 
.text           C:\WINDOWS\system32\ctfmon.exe[508] ntdll.dll!LdrLoadDll                                                                                                                          7C91632D 5 Bytes  JMP 000A01F8 
.text           C:\WINDOWS\system32\ctfmon.exe[508] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                            7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\ctfmon.exe[508] ntdll.dll!LdrUnloadDll                                                                                                                        7C9171CD 5 Bytes  JMP 000A03FC 
.text           C:\WINDOWS\system32\ctfmon.exe[508] kernel32.dll!GetBinaryTypeW + 80                                                                                                              7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\ctfmon.exe[508] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                         77E26D81 5 Bytes  JMP 00381014 
.text           C:\WINDOWS\system32\ctfmon.exe[508] ADVAPI32.dll!ChangeServiceConfigA                                                                                                             77E26E69 5 Bytes  JMP 00380804 
.text           C:\WINDOWS\system32\ctfmon.exe[508] ADVAPI32.dll!ChangeServiceConfigW                                                                                                             77E27001 5 Bytes  JMP 00380A08 
.text           C:\WINDOWS\system32\ctfmon.exe[508] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                            77E27101 5 Bytes  JMP 00380C0C 
.text           C:\WINDOWS\system32\ctfmon.exe[508] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                            77E27189 5 Bytes  JMP 00380E10 
.text           C:\WINDOWS\system32\ctfmon.exe[508] ADVAPI32.dll!CreateServiceA                                                                                                                   77E27211 5 Bytes  JMP 003801F8 
.text           C:\WINDOWS\system32\ctfmon.exe[508] ADVAPI32.dll!CreateServiceW                                                                                                                   77E273A9 5 Bytes  JMP 003803FC 
.text           C:\WINDOWS\system32\ctfmon.exe[508] ADVAPI32.dll!DeleteService                                                                                                                    77E274B1 5 Bytes  JMP 00380600 
.text           C:\WINDOWS\system32\ctfmon.exe[508] USER32.dll!SetWindowsHookExW                                                                                                                  7E37820F 5 Bytes  JMP 00390804 
.text           C:\WINDOWS\system32\ctfmon.exe[508] USER32.dll!UnhookWindowsHookEx                                                                                                                7E37D5F3 5 Bytes  JMP 00390A08 
.text           C:\WINDOWS\system32\ctfmon.exe[508] USER32.dll!SetWindowsHookExA                                                                                                                  7E381211 5 Bytes  JMP 00390600 
.text           C:\WINDOWS\system32\ctfmon.exe[508] USER32.dll!SetWinEventHook                                                                                                                    7E3817F7 5 Bytes  JMP 003901F8 
.text           C:\WINDOWS\system32\ctfmon.exe[508] USER32.dll!UnhookWinEvent                                                                                                                     7E3818AC 3 Bytes  JMP 003903FC 
.text           C:\WINDOWS\system32\ctfmon.exe[508] USER32.dll!UnhookWinEvent + 4                                                                                                                 7E3818B0 1 Byte  [82]
.text           C:\WINDOWS\System32\smss.exe[680] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                              7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\csrss.exe[940] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                             7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\csrss.exe[940] KERNEL32.dll!GetBinaryTypeW + 80                                                                                                               7C868D8C 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtCreateFile + 6                                         7C90D0B4 4 Bytes  [28, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtCreateFile + B                                         7C90D0B9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtMapViewOfSection + 6                                   7C90D524 1 Byte  [28]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtMapViewOfSection + 6                                   7C90D524 4 Bytes  [28, 03, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtMapViewOfSection + B                                   7C90D529 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtOpenFile + 6                                           7C90D5A4 4 Bytes  [68, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtOpenFile + B                                           7C90D5A9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtOpenProcess + 6                                        7C90D604 4 Bytes  [A8, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtOpenProcess + B                                        7C90D609 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtOpenProcessToken + 6                                   7C90D614 4 Bytes  CALL 7B90EC1A 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtOpenProcessToken + B                                   7C90D619 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtOpenProcessTokenEx + 6                                 7C90D624 4 Bytes  [A8, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtOpenProcessTokenEx + B                                 7C90D629 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtOpenThread + 6                                         7C90D664 4 Bytes  [68, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtOpenThread + B                                         7C90D669 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtOpenThreadToken + 6                                    7C90D674 4 Bytes  [68, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtOpenThreadToken + B                                    7C90D679 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtOpenThreadTokenEx + 6                                  7C90D684 4 Bytes  CALL 7B90EC8B 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtOpenThreadTokenEx + B                                  7C90D689 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtQueryAttributesFile + 6                                7C90D714 4 Bytes  [A8, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtQueryAttributesFile + B                                7C90D719 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtQueryFullAttributesFile + 6                            7C90D7B4 4 Bytes  CALL 7B90EDB9 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtQueryFullAttributesFile + B                            7C90D7B9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtSetInformationFile + 6                                 7C90DC64 4 Bytes  [28, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtSetInformationFile + B                                 7C90DC69 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtSetInformationThread + 6                               7C90DCB4 4 Bytes  [28, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtSetInformationThread + B                               7C90DCB9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtUnmapViewOfSection + 6                                 7C90DF14 1 Byte  [68]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtUnmapViewOfSection + 6                                 7C90DF14 4 Bytes  [68, 03, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!NtUnmapViewOfSection + B                                 7C90DF19 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!LdrLoadDll                                               7C91632D 5 Bytes  JMP 001801F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!RtlDosSearchPath_U + 186                                 7C916865 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ntdll.dll!LdrUnloadDll                                             7C9171CD 5 Bytes  JMP 001803FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] kernel32.dll!GetBinaryTypeW + 80                                   7C868D8C 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ADVAPI32.dll!SetServiceObjectSecurity                              77E26D81 5 Bytes  JMP 00571014 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ADVAPI32.dll!ChangeServiceConfigA                                  77E26E69 5 Bytes  JMP 00570804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ADVAPI32.dll!ChangeServiceConfigW                                  77E27001 5 Bytes  JMP 00570A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ADVAPI32.dll!ChangeServiceConfig2A                                 77E27101 5 Bytes  JMP 00570C0C 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ADVAPI32.dll!ChangeServiceConfig2W                                 77E27189 5 Bytes  JMP 00570E10 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ADVAPI32.dll!CreateServiceA                                        77E27211 5 Bytes  JMP 005701F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ADVAPI32.dll!CreateServiceW                                        77E273A9 5 Bytes  JMP 005703FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] ADVAPI32.dll!DeleteService                                         77E274B1 5 Bytes  JMP 00570600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] USER32.dll!SetWindowsHookExW                                       7E37820F 5 Bytes  JMP 00580804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] USER32.dll!UnhookWindowsHookEx                                     7E37D5F3 5 Bytes  JMP 00580A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] USER32.dll!SetWindowsHookExA                                       7E381211 5 Bytes  JMP 00580600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] USER32.dll!SetWinEventHook                                         7E3817F7 5 Bytes  JMP 005801F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] USER32.dll!UnhookWinEvent                                          7E3818AC 5 Bytes  JMP 005803FC 
.text           C:\WINDOWS\Explorer.EXE[960] ntdll.dll!LdrLoadDll                                                                                                                                 7C91632D 5 Bytes  JMP 000901F8 
.text           C:\WINDOWS\Explorer.EXE[960] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                                   7C916865 1 Byte  [62]
.text           C:\WINDOWS\Explorer.EXE[960] ntdll.dll!LdrUnloadDll                                                                                                                               7C9171CD 5 Bytes  JMP 000903FC 
.text           C:\WINDOWS\Explorer.EXE[960] kernel32.dll!GetBinaryTypeW + 80                                                                                                                     7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\Explorer.EXE[960] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                                77E26D81 5 Bytes  JMP 00381014 
.text           C:\WINDOWS\Explorer.EXE[960] ADVAPI32.dll!ChangeServiceConfigA                                                                                                                    77E26E69 5 Bytes  JMP 00380804 
.text           C:\WINDOWS\Explorer.EXE[960] ADVAPI32.dll!ChangeServiceConfigW                                                                                                                    77E27001 5 Bytes  JMP 00380A08 
.text           C:\WINDOWS\Explorer.EXE[960] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                                   77E27101 5 Bytes  JMP 00380C0C 
.text           C:\WINDOWS\Explorer.EXE[960] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                                   77E27189 5 Bytes  JMP 00380E10 
.text           C:\WINDOWS\Explorer.EXE[960] ADVAPI32.dll!CreateServiceA                                                                                                                          77E27211 5 Bytes  JMP 003801F8 
.text           C:\WINDOWS\Explorer.EXE[960] ADVAPI32.dll!CreateServiceW                                                                                                                          77E273A9 5 Bytes  JMP 003803FC 
.text           C:\WINDOWS\Explorer.EXE[960] ADVAPI32.dll!DeleteService                                                                                                                           77E274B1 5 Bytes  JMP 00380600 
.text           C:\WINDOWS\Explorer.EXE[960] USER32.dll!SetWindowsHookExW                                                                                                                         7E37820F 5 Bytes  JMP 00390804 
.text           C:\WINDOWS\Explorer.EXE[960] USER32.dll!UnhookWindowsHookEx                                                                                                                       7E37D5F3 5 Bytes  JMP 00390A08 
.text           C:\WINDOWS\Explorer.EXE[960] USER32.dll!SetWindowsHookExA                                                                                                                         7E381211 5 Bytes  JMP 00390600 
.text           C:\WINDOWS\Explorer.EXE[960] USER32.dll!SetWinEventHook                                                                                                                           7E3817F7 5 Bytes  JMP 003901F8 
.text           C:\WINDOWS\Explorer.EXE[960] USER32.dll!UnhookWinEvent                                                                                                                            7E3818AC 3 Bytes  JMP 003903FC 
.text           C:\WINDOWS\Explorer.EXE[960] USER32.dll!UnhookWinEvent + 4                                                                                                                        7E3818B0 1 Byte  [82]
.text           C:\WINDOWS\system32\winlogon.exe[996] ntdll.dll!LdrLoadDll                                                                                                                        7C91632D 5 Bytes  JMP 000701F8 
.text           C:\WINDOWS\system32\winlogon.exe[996] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                          7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\winlogon.exe[996] ntdll.dll!LdrUnloadDll                                                                                                                      7C9171CD 5 Bytes  JMP 000703FC 
.text           C:\WINDOWS\system32\winlogon.exe[996] kernel32.dll!GetBinaryTypeW + 80                                                                                                            7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\winlogon.exe[996] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                       77E26D81 5 Bytes  JMP 00301014 
.text           C:\WINDOWS\system32\winlogon.exe[996] ADVAPI32.dll!ChangeServiceConfigA                                                                                                           77E26E69 5 Bytes  JMP 00300804 
.text           C:\WINDOWS\system32\winlogon.exe[996] ADVAPI32.dll!ChangeServiceConfigW                                                                                                           77E27001 5 Bytes  JMP 00300A08 
.text           C:\WINDOWS\system32\winlogon.exe[996] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                          77E27101 5 Bytes  JMP 00300C0C 
.text           C:\WINDOWS\system32\winlogon.exe[996] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                          77E27189 5 Bytes  JMP 00300E10 
.text           C:\WINDOWS\system32\winlogon.exe[996] ADVAPI32.dll!CreateServiceA                                                                                                                 77E27211 5 Bytes  JMP 003001F8 
.text           C:\WINDOWS\system32\winlogon.exe[996] ADVAPI32.dll!CreateServiceW                                                                                                                 77E273A9 5 Bytes  JMP 003003FC 
.text           C:\WINDOWS\system32\winlogon.exe[996] ADVAPI32.dll!DeleteService                                                                                                                  77E274B1 5 Bytes  JMP 00300600 
.text           C:\WINDOWS\system32\winlogon.exe[996] USER32.dll!SetWindowsHookExW                                                                                                                7E37820F 5 Bytes  JMP 00310804 
.text           C:\WINDOWS\system32\winlogon.exe[996] USER32.dll!UnhookWindowsHookEx                                                                                                              7E37D5F3 5 Bytes  JMP 00310A08 
.text           C:\WINDOWS\system32\winlogon.exe[996] USER32.dll!SetWindowsHookExA                                                                                                                7E381211 5 Bytes  JMP 00310600 
.text           C:\WINDOWS\system32\winlogon.exe[996] USER32.dll!SetWinEventHook                                                                                                                  7E3817F7 5 Bytes  JMP 003101F8 
.text           C:\WINDOWS\system32\winlogon.exe[996] USER32.dll!UnhookWinEvent                                                                                                                   7E3818AC 5 Bytes  JMP 003103FC 
.text           C:\WINDOWS\system32\services.exe[1088] ntdll.dll!LdrLoadDll                                                                                                                       7C91632D 5 Bytes  JMP 000901F8 
.text           C:\WINDOWS\system32\services.exe[1088] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                         7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\services.exe[1088] ntdll.dll!LdrUnloadDll                                                                                                                     7C9171CD 5 Bytes  JMP 000903FC 
.text           C:\WINDOWS\system32\services.exe[1088] kernel32.dll!GetBinaryTypeW + 80                                                                                                           7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\services.exe[1088] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                      77E26D81 5 Bytes  JMP 00301014 
.text           C:\WINDOWS\system32\services.exe[1088] ADVAPI32.dll!ChangeServiceConfigA                                                                                                          77E26E69 5 Bytes  JMP 00300804 
.text           C:\WINDOWS\system32\services.exe[1088] ADVAPI32.dll!ChangeServiceConfigW                                                                                                          77E27001 5 Bytes  JMP 00300A08 
.text           C:\WINDOWS\system32\services.exe[1088] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                         77E27101 5 Bytes  JMP 00300C0C 
.text           C:\WINDOWS\system32\services.exe[1088] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                         77E27189 5 Bytes  JMP 00300E10 
.text           C:\WINDOWS\system32\services.exe[1088] ADVAPI32.dll!CreateServiceA                                                                                                                77E27211 5 Bytes  JMP 003001F8 
.text           C:\WINDOWS\system32\services.exe[1088] ADVAPI32.dll!CreateServiceW                                                                                                                77E273A9 5 Bytes  JMP 003003FC 
.text           C:\WINDOWS\system32\services.exe[1088] ADVAPI32.dll!DeleteService                                                                                                                 77E274B1 5 Bytes  JMP 00300600 
.text           C:\WINDOWS\system32\services.exe[1088] USER32.dll!SetWindowsHookExW                                                                                                               7E37820F 5 Bytes  JMP 00310804 
.text           C:\WINDOWS\system32\services.exe[1088] USER32.dll!UnhookWindowsHookEx                                                                                                             7E37D5F3 5 Bytes  JMP 00310A08 
.text           C:\WINDOWS\system32\services.exe[1088] USER32.dll!SetWindowsHookExA                                                                                                               7E381211 5 Bytes  JMP 00310600 
.text           C:\WINDOWS\system32\services.exe[1088] USER32.dll!SetWinEventHook                                                                                                                 7E3817F7 5 Bytes  JMP 003101F8 
.text           C:\WINDOWS\system32\services.exe[1088] USER32.dll!UnhookWinEvent                                                                                                                  7E3818AC 5 Bytes  JMP 003103FC 
.text           C:\WINDOWS\system32\lsass.exe[1100] ntdll.dll!LdrLoadDll                                                                                                                          7C91632D 5 Bytes  JMP 000901F8 
.text           C:\WINDOWS\system32\lsass.exe[1100] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                            7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\lsass.exe[1100] ntdll.dll!LdrUnloadDll                                                                                                                        7C9171CD 5 Bytes  JMP 000903FC 
.text           C:\WINDOWS\system32\lsass.exe[1100] kernel32.dll!GetBinaryTypeW + 80                                                                                                              7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\lsass.exe[1100] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                         77E26D81 5 Bytes  JMP 00301014 
.text           C:\WINDOWS\system32\lsass.exe[1100] ADVAPI32.dll!ChangeServiceConfigA                                                                                                             77E26E69 5 Bytes  JMP 00300804 
.text           C:\WINDOWS\system32\lsass.exe[1100] ADVAPI32.dll!ChangeServiceConfigW                                                                                                             77E27001 5 Bytes  JMP 00300A08 
.text           C:\WINDOWS\system32\lsass.exe[1100] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                            77E27101 5 Bytes  JMP 00300C0C 
.text           C:\WINDOWS\system32\lsass.exe[1100] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                            77E27189 5 Bytes  JMP 00300E10 
.text           C:\WINDOWS\system32\lsass.exe[1100] ADVAPI32.dll!CreateServiceA                                                                                                                   77E27211 5 Bytes  JMP 003001F8 
.text           C:\WINDOWS\system32\lsass.exe[1100] ADVAPI32.dll!CreateServiceW                                                                                                                   77E273A9 5 Bytes  JMP 003003FC 
.text           C:\WINDOWS\system32\lsass.exe[1100] ADVAPI32.dll!DeleteService                                                                                                                    77E274B1 5 Bytes  JMP 00300600 
.text           C:\WINDOWS\system32\lsass.exe[1100] USER32.dll!SetWindowsHookExW                                                                                                                  7E37820F 5 Bytes  JMP 00310804 
.text           C:\WINDOWS\system32\lsass.exe[1100] USER32.dll!UnhookWindowsHookEx                                                                                                                7E37D5F3 5 Bytes  JMP 00310A08 
.text           C:\WINDOWS\system32\lsass.exe[1100] USER32.dll!SetWindowsHookExA                                                                                                                  7E381211 5 Bytes  JMP 00310600 
.text           C:\WINDOWS\system32\lsass.exe[1100] USER32.dll!SetWinEventHook                                                                                                                    7E3817F7 5 Bytes  JMP 003101F8 
.text           C:\WINDOWS\system32\lsass.exe[1100] USER32.dll!UnhookWinEvent                                                                                                                     7E3818AC 5 Bytes  JMP 003103FC 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] ntdll.dll!LdrLoadDll                                                                               7C91632D 5 Bytes  JMP 001501F8 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] ntdll.dll!RtlDosSearchPath_U + 186                                                                 7C916865 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] ntdll.dll!LdrUnloadDll                                                                             7C9171CD 5 Bytes  JMP 001503FC 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] kernel32.dll!GetBinaryTypeW + 80                                                                   7C868D8C 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] ADVAPI32.dll!SetServiceObjectSecurity                                                              77E26D81 5 Bytes  JMP 009C1014 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] ADVAPI32.dll!ChangeServiceConfigA                                                                  77E26E69 5 Bytes  JMP 009C0804 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] ADVAPI32.dll!ChangeServiceConfigW                                                                  77E27001 5 Bytes  JMP 009C0A08 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] ADVAPI32.dll!ChangeServiceConfig2A                                                                 77E27101 5 Bytes  JMP 009C0C0C 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] ADVAPI32.dll!ChangeServiceConfig2W                                                                 77E27189 5 Bytes  JMP 009C0E10 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] ADVAPI32.dll!CreateServiceA                                                                        77E27211 5 Bytes  JMP 009C01F8 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] ADVAPI32.dll!CreateServiceW                                                                        77E273A9 5 Bytes  JMP 009C03FC 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] ADVAPI32.dll!DeleteService                                                                         77E274B1 5 Bytes  JMP 009C0600 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] USER32.dll!SetWindowsHookExW                                                                       7E37820F 5 Bytes  JMP 009D0804 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] USER32.dll!UnhookWindowsHookEx                                                                     7E37D5F3 5 Bytes  JMP 009D0A08 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] USER32.dll!SetWindowsHookExA                                                                       7E381211 5 Bytes  JMP 009D0600 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] USER32.dll!SetWinEventHook                                                                         7E3817F7 5 Bytes  JMP 009D01F8 
.text           C:\Documents and Settings\Gr2eg0rz\Moje dokumenty\Downloads\bnih5s0s.exe[1224] USER32.dll!UnhookWinEvent                                                                          7E3818AC 5 Bytes  JMP 009D03FC 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] ntdll.dll!LdrLoadDll                                                                                                                       7C91632D 5 Bytes  JMP 000901F8 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                         7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] ntdll.dll!LdrUnloadDll                                                                                                                     7C9171CD 5 Bytes  JMP 000903FC 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] kernel32.dll!GetBinaryTypeW + 80                                                                                                           7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] USER32.dll!SetWindowsHookExW                                                                                                               7E37820F 5 Bytes  JMP 00300804 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] USER32.dll!UnhookWindowsHookEx                                                                                                             7E37D5F3 5 Bytes  JMP 00300A08 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] USER32.dll!SetWindowsHookExA                                                                                                               7E381211 5 Bytes  JMP 00300600 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] USER32.dll!SetWinEventHook                                                                                                                 7E3817F7 5 Bytes  JMP 003001F8 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] USER32.dll!UnhookWinEvent                                                                                                                  7E3818AC 5 Bytes  JMP 003003FC 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                      77E26D81 5 Bytes  JMP 00311014 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] ADVAPI32.dll!ChangeServiceConfigA                                                                                                          77E26E69 5 Bytes  JMP 00310804 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] ADVAPI32.dll!ChangeServiceConfigW                                                                                                          77E27001 5 Bytes  JMP 00310A08 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                         77E27101 5 Bytes  JMP 00310C0C 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                         77E27189 5 Bytes  JMP 00310E10 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] ADVAPI32.dll!CreateServiceA                                                                                                                77E27211 5 Bytes  JMP 003101F8 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] ADVAPI32.dll!CreateServiceW                                                                                                                77E273A9 5 Bytes  JMP 003103FC 
.text           C:\WINDOWS\system32\RunDLL32.exe[1260] ADVAPI32.dll!DeleteService                                                                                                                 77E274B1 5 Bytes  JMP 00310600 
.text           C:\WINDOWS\system32\svchost.exe[1304] ntdll.dll!LdrLoadDll                                                                                                                        7C91632D 5 Bytes  JMP 000901F8 
.text           C:\WINDOWS\system32\svchost.exe[1304] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                          7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1304] ntdll.dll!LdrUnloadDll                                                                                                                      7C9171CD 5 Bytes  JMP 000903FC 
.text           C:\WINDOWS\system32\svchost.exe[1304] kernel32.dll!GetBinaryTypeW + 80                                                                                                            7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                       77E26D81 5 Bytes  JMP 00301014 
.text           C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!ChangeServiceConfigA                                                                                                           77E26E69 5 Bytes  JMP 00300804 
.text           C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!ChangeServiceConfigW                                                                                                           77E27001 5 Bytes  JMP 00300A08 
.text           C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                          77E27101 5 Bytes  JMP 00300C0C 
.text           C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                          77E27189 5 Bytes  JMP 00300E10 
.text           C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!CreateServiceA                                                                                                                 77E27211 5 Bytes  JMP 003001F8 
.text           C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!CreateServiceW                                                                                                                 77E273A9 5 Bytes  JMP 003003FC 
.text           C:\WINDOWS\system32\svchost.exe[1304] ADVAPI32.dll!DeleteService                                                                                                                  77E274B1 5 Bytes  JMP 00300600 
.text           C:\WINDOWS\system32\svchost.exe[1304] USER32.dll!SetWindowsHookExW                                                                                                                7E37820F 5 Bytes  JMP 00310804 
.text           C:\WINDOWS\system32\svchost.exe[1304] USER32.dll!UnhookWindowsHookEx                                                                                                              7E37D5F3 5 Bytes  JMP 00310A08 
.text           C:\WINDOWS\system32\svchost.exe[1304] USER32.dll!SetWindowsHookExA                                                                                                                7E381211 5 Bytes  JMP 00310600 
.text           C:\WINDOWS\system32\svchost.exe[1304] USER32.dll!SetWinEventHook                                                                                                                  7E3817F7 5 Bytes  JMP 003101F8 
.text           C:\WINDOWS\system32\svchost.exe[1304] USER32.dll!UnhookWinEvent                                                                                                                   7E3818AC 5 Bytes  JMP 003103FC 
.text           C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!LdrLoadDll                                                                                                                        7C91632D 5 Bytes  JMP 000901F8 
.text           C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                          7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1412] ntdll.dll!LdrUnloadDll                                                                                                                      7C9171CD 5 Bytes  JMP 000903FC 
.text           C:\WINDOWS\system32\svchost.exe[1412] kernel32.dll!GetBinaryTypeW + 80                                                                                                            7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                       77E26D81 5 Bytes  JMP 00301014 
.text           C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!ChangeServiceConfigA                                                                                                           77E26E69 5 Bytes  JMP 00300804 
.text           C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!ChangeServiceConfigW                                                                                                           77E27001 5 Bytes  JMP 00300A08 
.text           C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                          77E27101 5 Bytes  JMP 00300C0C 
.text           C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                          77E27189 5 Bytes  JMP 00300E10 
.text           C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!CreateServiceA                                                                                                                 77E27211 5 Bytes  JMP 003001F8 
.text           C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!CreateServiceW                                                                                                                 77E273A9 5 Bytes  JMP 003003FC 
.text           C:\WINDOWS\system32\svchost.exe[1412] ADVAPI32.dll!DeleteService                                                                                                                  77E274B1 5 Bytes  JMP 00300600 
.text           C:\WINDOWS\system32\svchost.exe[1412] USER32.dll!SetWindowsHookExW                                                                                                                7E37820F 5 Bytes  JMP 00310804 
.text           C:\WINDOWS\system32\svchost.exe[1412] USER32.dll!UnhookWindowsHookEx                                                                                                              7E37D5F3 5 Bytes  JMP 00310A08 
.text           C:\WINDOWS\system32\svchost.exe[1412] USER32.dll!SetWindowsHookExA                                                                                                                7E381211 5 Bytes  JMP 00310600 
.text           C:\WINDOWS\system32\svchost.exe[1412] USER32.dll!SetWinEventHook                                                                                                                  7E3817F7 5 Bytes  JMP 003101F8 
.text           C:\WINDOWS\system32\svchost.exe[1412] USER32.dll!UnhookWinEvent                                                                                                                   7E3818AC 5 Bytes  JMP 003103FC 
.text           C:\WINDOWS\System32\svchost.exe[1472] ntdll.dll!LdrLoadDll                                                                                                                        7C91632D 5 Bytes  JMP 000901F8 
.text           C:\WINDOWS\System32\svchost.exe[1472] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                          7C916865 1 Byte  [62]
.text           C:\WINDOWS\System32\svchost.exe[1472] ntdll.dll!LdrUnloadDll                                                                                                                      7C9171CD 5 Bytes  JMP 000903FC 
.text           C:\WINDOWS\System32\svchost.exe[1472] kernel32.dll!GetBinaryTypeW + 80                                                                                                            7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\System32\svchost.exe[1472] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                       77E26D81 5 Bytes  JMP 00301014 
.text           C:\WINDOWS\System32\svchost.exe[1472] ADVAPI32.dll!ChangeServiceConfigA                                                                                                           77E26E69 5 Bytes  JMP 00300804 
.text           C:\WINDOWS\System32\svchost.exe[1472] ADVAPI32.dll!ChangeServiceConfigW                                                                                                           77E27001 5 Bytes  JMP 00300A08 
.text           C:\WINDOWS\System32\svchost.exe[1472] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                          77E27101 5 Bytes  JMP 00300C0C 
.text           C:\WINDOWS\System32\svchost.exe[1472] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                          77E27189 5 Bytes  JMP 00300E10 
.text           C:\WINDOWS\System32\svchost.exe[1472] ADVAPI32.dll!CreateServiceA                                                                                                                 77E27211 5 Bytes  JMP 003001F8 
.text           C:\WINDOWS\System32\svchost.exe[1472] ADVAPI32.dll!CreateServiceW                                                                                                                 77E273A9 5 Bytes  JMP 003003FC 
.text           C:\WINDOWS\System32\svchost.exe[1472] ADVAPI32.dll!DeleteService                                                                                                                  77E274B1 5 Bytes  JMP 00300600 
.text           C:\WINDOWS\System32\svchost.exe[1472] USER32.dll!SetWindowsHookExW                                                                                                                7E37820F 5 Bytes  JMP 00310804 
.text           C:\WINDOWS\System32\svchost.exe[1472] USER32.dll!UnhookWindowsHookEx                                                                                                              7E37D5F3 5 Bytes  JMP 00310A08 
.text           C:\WINDOWS\System32\svchost.exe[1472] USER32.dll!SetWindowsHookExA                                                                                                                7E381211 5 Bytes  JMP 00310600 
.text           C:\WINDOWS\System32\svchost.exe[1472] USER32.dll!SetWinEventHook                                                                                                                  7E3817F7 5 Bytes  JMP 003101F8 
.text           C:\WINDOWS\System32\svchost.exe[1472] USER32.dll!UnhookWinEvent                                                                                                                   7E3818AC 5 Bytes  JMP 003103FC 
.text           C:\WINDOWS\system32\svchost.exe[1564] ntdll.dll!LdrLoadDll                                                                                                                        7C91632D 5 Bytes  JMP 000901F8 
.text           C:\WINDOWS\system32\svchost.exe[1564] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                          7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1564] ntdll.dll!LdrUnloadDll                                                                                                                      7C9171CD 5 Bytes  JMP 000903FC 
.text           C:\WINDOWS\system32\svchost.exe[1564] kernel32.dll!GetBinaryTypeW + 80                                                                                                            7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1564] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                       77E26D81 5 Bytes  JMP 00301014 
.text           C:\WINDOWS\system32\svchost.exe[1564] ADVAPI32.dll!ChangeServiceConfigA                                                                                                           77E26E69 5 Bytes  JMP 00300804 
.text           C:\WINDOWS\system32\svchost.exe[1564] ADVAPI32.dll!ChangeServiceConfigW                                                                                                           77E27001 5 Bytes  JMP 00300A08 
.text           C:\WINDOWS\system32\svchost.exe[1564] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                          77E27101 5 Bytes  JMP 00300C0C 
.text           C:\WINDOWS\system32\svchost.exe[1564] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                          77E27189 5 Bytes  JMP 00300E10 
.text           C:\WINDOWS\system32\svchost.exe[1564] ADVAPI32.dll!CreateServiceA                                                                                                                 77E27211 5 Bytes  JMP 003001F8 
.text           C:\WINDOWS\system32\svchost.exe[1564] ADVAPI32.dll!CreateServiceW                                                                                                                 77E273A9 5 Bytes  JMP 003003FC 
.text           C:\WINDOWS\system32\svchost.exe[1564] ADVAPI32.dll!DeleteService                                                                                                                  77E274B1 5 Bytes  JMP 00300600 
.text           C:\WINDOWS\system32\svchost.exe[1564] USER32.dll!SetWindowsHookExW                                                                                                                7E37820F 5 Bytes  JMP 00310804 
.text           C:\WINDOWS\system32\svchost.exe[1564] USER32.dll!UnhookWindowsHookEx                                                                                                              7E37D5F3 5 Bytes  JMP 00310A08 
.text           C:\WINDOWS\system32\svchost.exe[1564] USER32.dll!SetWindowsHookExA                                                                                                                7E381211 5 Bytes  JMP 00310600 
.text           C:\WINDOWS\system32\svchost.exe[1564] USER32.dll!SetWinEventHook                                                                                                                  7E3817F7 5 Bytes  JMP 003101F8 
.text           C:\WINDOWS\system32\svchost.exe[1564] USER32.dll!UnhookWinEvent                                                                                                                   7E3818AC 5 Bytes  JMP 003103FC 
.text           C:\WINDOWS\system32\svchost.exe[1656] ntdll.dll!LdrLoadDll                                                                                                                        7C91632D 5 Bytes  JMP 000901F8 
.text           C:\WINDOWS\system32\svchost.exe[1656] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                          7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1656] ntdll.dll!LdrUnloadDll                                                                                                                      7C9171CD 5 Bytes  JMP 000903FC 
.text           C:\WINDOWS\system32\svchost.exe[1656] kernel32.dll!GetBinaryTypeW + 80                                                                                                            7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[1656] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                       77E26D81 5 Bytes  JMP 00301014 
.text           C:\WINDOWS\system32\svchost.exe[1656] ADVAPI32.dll!ChangeServiceConfigA                                                                                                           77E26E69 5 Bytes  JMP 00300804 
.text           C:\WINDOWS\system32\svchost.exe[1656] ADVAPI32.dll!ChangeServiceConfigW                                                                                                           77E27001 5 Bytes  JMP 00300A08 
.text           C:\WINDOWS\system32\svchost.exe[1656] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                          77E27101 5 Bytes  JMP 00300C0C 
.text           C:\WINDOWS\system32\svchost.exe[1656] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                          77E27189 5 Bytes  JMP 00300E10 
.text           C:\WINDOWS\system32\svchost.exe[1656] ADVAPI32.dll!CreateServiceA                                                                                                                 77E27211 5 Bytes  JMP 003001F8 
.text           C:\WINDOWS\system32\svchost.exe[1656] ADVAPI32.dll!CreateServiceW                                                                                                                 77E273A9 5 Bytes  JMP 003003FC 
.text           C:\WINDOWS\system32\svchost.exe[1656] ADVAPI32.dll!DeleteService                                                                                                                  77E274B1 5 Bytes  JMP 00300600 
.text           C:\WINDOWS\system32\svchost.exe[1656] USER32.dll!SetWindowsHookExW                                                                                                                7E37820F 5 Bytes  JMP 00310804 
.text           C:\WINDOWS\system32\svchost.exe[1656] USER32.dll!UnhookWindowsHookEx                                                                                                              7E37D5F3 5 Bytes  JMP 00310A08 
.text           C:\WINDOWS\system32\svchost.exe[1656] USER32.dll!SetWindowsHookExA                                                                                                                7E381211 5 Bytes  JMP 00310600 
.text           C:\WINDOWS\system32\svchost.exe[1656] USER32.dll!SetWinEventHook                                                                                                                  7E3817F7 5 Bytes  JMP 003101F8 
.text           C:\WINDOWS\system32\svchost.exe[1656] USER32.dll!UnhookWinEvent                                                                                                                   7E3818AC 5 Bytes  JMP 003103FC 
.text           C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1744] ntdll.dll!RtlDosSearchPath_U + 186                                                                                       7C916865 1 Byte  [62]
.text           C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1744] kernel32.dll!SetUnhandledExceptionFilter                                                                                 7C84495D 4 Bytes  [C2, 04, 00, 90] {RET 0x4; NOP }
.text           C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1744] kernel32.dll!GetBinaryTypeW + 80                                                                                         7C868D8C 1 Byte  [62]
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] ntdll.dll!LdrLoadDll                                                                               7C91632D 5 Bytes  JMP 000801F8 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] ntdll.dll!RtlDosSearchPath_U + 186                                                                 7C916865 1 Byte  [62]
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] ntdll.dll!LdrUnloadDll                                                                             7C9171CD 5 Bytes  JMP 000803FC 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] kernel32.dll!GetBinaryTypeW + 80                                                                   7C868D8C 1 Byte  [62]
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] ADVAPI32.dll!SetServiceObjectSecurity                                                              77E26D81 5 Bytes  JMP 00311014 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] ADVAPI32.dll!ChangeServiceConfigA                                                                  77E26E69 5 Bytes  JMP 00310804 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] ADVAPI32.dll!ChangeServiceConfigW                                                                  77E27001 5 Bytes  JMP 00310A08 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] ADVAPI32.dll!ChangeServiceConfig2A                                                                 77E27101 5 Bytes  JMP 00310C0C 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] ADVAPI32.dll!ChangeServiceConfig2W                                                                 77E27189 5 Bytes  JMP 00310E10 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] ADVAPI32.dll!CreateServiceA                                                                        77E27211 5 Bytes  JMP 003101F8 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] ADVAPI32.dll!CreateServiceW                                                                        77E273A9 5 Bytes  JMP 003103FC 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] ADVAPI32.dll!DeleteService                                                                         77E274B1 5 Bytes  JMP 00310600 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] USER32.dll!SetWindowsHookExW                                                                       7E37820F 5 Bytes  JMP 00320804 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] USER32.dll!UnhookWindowsHookEx                                                                     7E37D5F3 5 Bytes  JMP 00320A08 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] USER32.dll!SetWindowsHookExA                                                                       7E381211 5 Bytes  JMP 00320600 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] USER32.dll!SetWinEventHook                                                                         7E3817F7 5 Bytes  JMP 003201F8 
.text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[1772] USER32.dll!UnhookWinEvent                                                                          7E3818AC 5 Bytes  JMP 003203FC 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] ntdll.dll!LdrLoadDll                                                                                                                        7C91632D 5 Bytes  JMP 000901F8 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                          7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\spoolsv.exe[1836] ntdll.dll!LdrUnloadDll                                                                                                                      7C9171CD 5 Bytes  JMP 000903FC 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] kernel32.dll!GetBinaryTypeW + 80                                                                                                            7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\spoolsv.exe[1836] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                       77E26D81 5 Bytes  JMP 00301014 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] ADVAPI32.dll!ChangeServiceConfigA                                                                                                           77E26E69 5 Bytes  JMP 00300804 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] ADVAPI32.dll!ChangeServiceConfigW                                                                                                           77E27001 5 Bytes  JMP 00300A08 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                          77E27101 5 Bytes  JMP 00300C0C 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                          77E27189 5 Bytes  JMP 00300E10 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] ADVAPI32.dll!CreateServiceA                                                                                                                 77E27211 5 Bytes  JMP 003001F8 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] ADVAPI32.dll!CreateServiceW                                                                                                                 77E273A9 5 Bytes  JMP 003003FC 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] ADVAPI32.dll!DeleteService                                                                                                                  77E274B1 5 Bytes  JMP 00300600 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] USER32.dll!SetWindowsHookExW                                                                                                                7E37820F 5 Bytes  JMP 00310804 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] USER32.dll!UnhookWindowsHookEx                                                                                                              7E37D5F3 5 Bytes  JMP 00310A08 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] USER32.dll!SetWindowsHookExA                                                                                                                7E381211 5 Bytes  JMP 00310600 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] USER32.dll!SetWinEventHook                                                                                                                  7E3817F7 5 Bytes  JMP 003101F8 
.text           C:\WINDOWS\system32\spoolsv.exe[1836] USER32.dll!UnhookWinEvent                                                                                                                   7E3818AC 5 Bytes  JMP 003103FC 
.text           C:\Documents and Settings\All Users\Dane aplikacji\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe[1948] ntdll.dll!RtlDosSearchPath_U + 186                                7C916865 1 Byte  [62]
.text           C:\Documents and Settings\All Users\Dane aplikacji\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe[1948] KERNEL32.dll!GetBinaryTypeW + 80                                  7C868D8C 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtCreateFile + 6                                        7C90D0B4 4 Bytes  [28, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtCreateFile + B                                        7C90D0B9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 1 Byte  [28]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 4 Bytes  [28, 03, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtMapViewOfSection + B                                  7C90D529 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenFile + 6                                          7C90D5A4 4 Bytes  [68, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenFile + B                                          7C90D5A9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenProcess + 6                                       7C90D604 4 Bytes  [A8, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenProcess + B                                       7C90D609 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenProcessToken + 6                                  7C90D614 4 Bytes  CALL 7B90EC1A 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenProcessToken + B                                  7C90D619 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenProcessTokenEx + 6                                7C90D624 4 Bytes  [A8, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenProcessTokenEx + B                                7C90D629 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenThread + 6                                        7C90D664 4 Bytes  [68, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenThread + B                                        7C90D669 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenThreadToken + 6                                   7C90D674 4 Bytes  [68, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenThreadToken + B                                   7C90D679 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenThreadTokenEx + 6                                 7C90D684 4 Bytes  CALL 7B90EC8B 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtOpenThreadTokenEx + B                                 7C90D689 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtQueryAttributesFile + 6                               7C90D714 4 Bytes  [A8, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtQueryAttributesFile + B                               7C90D719 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtQueryFullAttributesFile + 6                           7C90D7B4 4 Bytes  CALL 7B90EDB9 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtQueryFullAttributesFile + B                           7C90D7B9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtSetInformationFile + 6                                7C90DC64 4 Bytes  [28, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtSetInformationFile + B                                7C90DC69 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtSetInformationThread + 6                              7C90DCB4 4 Bytes  [28, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtSetInformationThread + B                              7C90DCB9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 1 Byte  [68]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 4 Bytes  [68, 03, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!NtUnmapViewOfSection + B                                7C90DF19 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!LdrLoadDll                                              7C91632D 5 Bytes  JMP 001801F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!RtlDosSearchPath_U + 186                                7C916865 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ntdll.dll!LdrUnloadDll                                            7C9171CD 5 Bytes  JMP 001803FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] kernel32.dll!GetBinaryTypeW + 80                                  7C868D8C 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ADVAPI32.dll!SetServiceObjectSecurity                             77E26D81 5 Bytes  JMP 00571014 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ADVAPI32.dll!ChangeServiceConfigA                                 77E26E69 5 Bytes  JMP 00570804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ADVAPI32.dll!ChangeServiceConfigW                                 77E27001 5 Bytes  JMP 00570A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ADVAPI32.dll!ChangeServiceConfig2A                                77E27101 5 Bytes  JMP 00570C0C 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ADVAPI32.dll!ChangeServiceConfig2W                                77E27189 5 Bytes  JMP 00570E10 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ADVAPI32.dll!CreateServiceA                                       77E27211 5 Bytes  JMP 005701F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ADVAPI32.dll!CreateServiceW                                       77E273A9 5 Bytes  JMP 005703FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] ADVAPI32.dll!DeleteService                                        77E274B1 5 Bytes  JMP 00570600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] USER32.dll!SetWindowsHookExW                                      7E37820F 5 Bytes  JMP 00580804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] USER32.dll!UnhookWindowsHookEx                                    7E37D5F3 5 Bytes  JMP 00580A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] USER32.dll!SetWindowsHookExA                                      7E381211 5 Bytes  JMP 00580600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] USER32.dll!SetWinEventHook                                        7E3817F7 5 Bytes  JMP 005801F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] USER32.dll!UnhookWinEvent                                         7E3818AC 5 Bytes  JMP 005803FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtCreateFile + 6                                        7C90D0B4 4 Bytes  [28, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtCreateFile + B                                        7C90D0B9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 1 Byte  [28]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 4 Bytes  [28, 03, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtMapViewOfSection + B                                  7C90D529 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtOpenFile + 6                                          7C90D5A4 4 Bytes  [68, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtOpenFile + B                                          7C90D5A9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtOpenProcess + 6                                       7C90D604 4 Bytes  [A8, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtOpenProcess + B                                       7C90D609 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtOpenProcessToken + 6                                  7C90D614 4 Bytes  CALL 7B90EC1A 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtOpenProcessToken + B                                  7C90D619 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtOpenProcessTokenEx + 6                                7C90D624 4 Bytes  [A8, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtOpenProcessTokenEx + B                                7C90D629 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtOpenThread + 6                                        7C90D664 4 Bytes  [68, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtOpenThread + B                                        7C90D669 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtOpenThreadToken + 6                                   7C90D674 4 Bytes  [68, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtOpenThreadToken + B                                   7C90D679 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtOpenThreadTokenEx + 6                                 7C90D684 4 Bytes  CALL 7B90EC8B 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtOpenThreadTokenEx + B                                 7C90D689 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtQueryAttributesFile + 6                               7C90D714 4 Bytes  [A8, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtQueryAttributesFile + B                               7C90D719 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtQueryFullAttributesFile + 6                           7C90D7B4 4 Bytes  CALL 7B90EDB9 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtQueryFullAttributesFile + B                           7C90D7B9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtSetInformationFile + 6                                7C90DC64 4 Bytes  [28, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtSetInformationFile + B                                7C90DC69 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtSetInformationThread + 6                              7C90DCB4 4 Bytes  [28, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtSetInformationThread + B                              7C90DCB9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 1 Byte  [68]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 4 Bytes  [68, 03, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!NtUnmapViewOfSection + B                                7C90DF19 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!LdrLoadDll                                              7C91632D 5 Bytes  JMP 001801F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!RtlDosSearchPath_U + 186                                7C916865 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ntdll.dll!LdrUnloadDll                                            7C9171CD 5 Bytes  JMP 001803FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] kernel32.dll!GetBinaryTypeW + 80                                  7C868D8C 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ADVAPI32.dll!SetServiceObjectSecurity                             77E26D81 5 Bytes  JMP 00571014 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ADVAPI32.dll!ChangeServiceConfigA                                 77E26E69 5 Bytes  JMP 00570804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ADVAPI32.dll!ChangeServiceConfigW                                 77E27001 5 Bytes  JMP 00570A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ADVAPI32.dll!ChangeServiceConfig2A                                77E27101 5 Bytes  JMP 00570C0C 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ADVAPI32.dll!ChangeServiceConfig2W                                77E27189 5 Bytes  JMP 00570E10 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ADVAPI32.dll!CreateServiceA                                       77E27211 5 Bytes  JMP 005701F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ADVAPI32.dll!CreateServiceW                                       77E273A9 5 Bytes  JMP 005703FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] ADVAPI32.dll!DeleteService                                        77E274B1 5 Bytes  JMP 00570600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] USER32.dll!SetWindowsHookExW                                      7E37820F 5 Bytes  JMP 00580804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] USER32.dll!UnhookWindowsHookEx                                    7E37D5F3 5 Bytes  JMP 00580A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] USER32.dll!SetWindowsHookExA                                      7E381211 5 Bytes  JMP 00580600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] USER32.dll!SetWinEventHook                                        7E3817F7 5 Bytes  JMP 005801F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] USER32.dll!UnhookWinEvent                                         7E3818AC 5 Bytes  JMP 005803FC 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] ntdll.dll!LdrLoadDll                                                                                                    7C91632D 5 Bytes  JMP 000501F8 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] ntdll.dll!RtlDosSearchPath_U + 186                                                                                      7C916865 1 Byte  [62]
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] ntdll.dll!LdrUnloadDll                                                                                                  7C9171CD 5 Bytes  JMP 000503FC 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] kernel32.dll!GetBinaryTypeW + 80                                                                                        7C868D8C 1 Byte  [62]
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] ADVAPI32.dll!SetServiceObjectSecurity                                                                                   77E26D81 5 Bytes  JMP 01AA1014 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] ADVAPI32.dll!ChangeServiceConfigA                                                                                       77E26E69 5 Bytes  JMP 01AA0804 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] ADVAPI32.dll!ChangeServiceConfigW                                                                                       77E27001 5 Bytes  JMP 01AA0A08 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] ADVAPI32.dll!ChangeServiceConfig2A                                                                                      77E27101 5 Bytes  JMP 01AA0C0C 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] ADVAPI32.dll!ChangeServiceConfig2W                                                                                      77E27189 5 Bytes  JMP 01AA0E10 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] ADVAPI32.dll!CreateServiceA                                                                                             77E27211 5 Bytes  JMP 01AA01F8 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] ADVAPI32.dll!CreateServiceW                                                                                             77E273A9 5 Bytes  JMP 01AA03FC 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] ADVAPI32.dll!DeleteService                                                                                              77E274B1 5 Bytes  JMP 01AA0600 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] USER32.dll!SetWindowsHookExW                                                                                            7E37820F 5 Bytes  JMP 01AB0804 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] USER32.dll!UnhookWindowsHookEx                                                                                          7E37D5F3 5 Bytes  JMP 01AB0A08 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] USER32.dll!SetWindowsHookExA                                                                                            7E381211 5 Bytes  JMP 01AB0600 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] USER32.dll!SetWinEventHook                                                                                              7E3817F7 5 Bytes  JMP 01AB01F8 
.text           C:\Program Files\TuneUp Utilities 2012\OneClick.exe[2476] USER32.dll!UnhookWinEvent                                                                                               7E3818AC 5 Bytes  JMP 01AB03FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] ntdll.dll!LdrLoadDll                                              7C91632D 5 Bytes  JMP 001501F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] ntdll.dll!RtlDosSearchPath_U + 186                                7C916865 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] ntdll.dll!LdrUnloadDll                                            7C9171CD 5 Bytes  JMP 001503FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] kernel32.dll!GetBinaryTypeW + 80                                  7C868D8C 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] ADVAPI32.dll!SetServiceObjectSecurity                             77E26D81 5 Bytes  JMP 003E1014 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] ADVAPI32.dll!ChangeServiceConfigA                                 77E26E69 5 Bytes  JMP 003E0804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] ADVAPI32.dll!ChangeServiceConfigW                                 77E27001 5 Bytes  JMP 003E0A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] ADVAPI32.dll!ChangeServiceConfig2A                                77E27101 5 Bytes  JMP 003E0C0C 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] ADVAPI32.dll!ChangeServiceConfig2W                                77E27189 5 Bytes  JMP 003E0E10 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] ADVAPI32.dll!CreateServiceA                                       77E27211 5 Bytes  JMP 003E01F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] ADVAPI32.dll!CreateServiceW                                       77E273A9 5 Bytes  JMP 003E03FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] ADVAPI32.dll!DeleteService                                        77E274B1 5 Bytes  JMP 003E0600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] USER32.dll!SetWindowsHookExW                                      7E37820F 5 Bytes  JMP 003F0804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] USER32.dll!UnhookWindowsHookEx                                    7E37D5F3 5 Bytes  JMP 003F0A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] USER32.dll!SetWindowsHookExA                                      7E381211 5 Bytes  JMP 003F0600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] USER32.dll!SetWinEventHook                                        7E3817F7 5 Bytes  JMP 003F01F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2512] USER32.dll!UnhookWinEvent                                         7E3818AC 5 Bytes  JMP 003F03FC 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] ntdll.dll!LdrLoadDll                                                                                        7C91632D 5 Bytes  JMP 001501F8 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] ntdll.dll!RtlDosSearchPath_U + 186                                                                          7C916865 1 Byte  [62]
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] ntdll.dll!LdrUnloadDll                                                                                      7C9171CD 5 Bytes  JMP 001503FC 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] kernel32.dll!GetBinaryTypeW + 80                                                                            7C868D8C 1 Byte  [62]
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] USER32.dll!SetWindowsHookExW                                                                                7E37820F 5 Bytes  JMP 003E0804 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] USER32.dll!UnhookWindowsHookEx                                                                              7E37D5F3 5 Bytes  JMP 003E0A08 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] USER32.dll!SetWindowsHookExA                                                                                7E381211 5 Bytes  JMP 003E0600 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] USER32.dll!SetWinEventHook                                                                                  7E3817F7 5 Bytes  JMP 003E01F8 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] USER32.dll!UnhookWinEvent                                                                                   7E3818AC 5 Bytes  JMP 003E03FC 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] ADVAPI32.dll!SetServiceObjectSecurity                                                                       77E26D81 5 Bytes  JMP 003F1014 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] ADVAPI32.dll!ChangeServiceConfigA                                                                           77E26E69 5 Bytes  JMP 003F0804 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] ADVAPI32.dll!ChangeServiceConfigW                                                                           77E27001 5 Bytes  JMP 003F0A08 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] ADVAPI32.dll!ChangeServiceConfig2A                                                                          77E27101 5 Bytes  JMP 003F0C0C 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] ADVAPI32.dll!ChangeServiceConfig2W                                                                          77E27189 5 Bytes  JMP 003F0E10 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] ADVAPI32.dll!CreateServiceA                                                                                 77E27211 5 Bytes  JMP 003F01F8 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] ADVAPI32.dll!CreateServiceW                                                                                 77E273A9 5 Bytes  JMP 003F03FC 
.text           C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe[2524] ADVAPI32.dll!DeleteService                                                                                  77E274B1 5 Bytes  JMP 003F0600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] ntdll.dll!LdrLoadDll                                              7C91632D 5 Bytes  JMP 001501F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] ntdll.dll!RtlDosSearchPath_U + 186                                7C916865 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] ntdll.dll!LdrUnloadDll                                            7C9171CD 5 Bytes  JMP 001503FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] kernel32.dll!GetBinaryTypeW + 80                                  7C868D8C 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] ADVAPI32.dll!SetServiceObjectSecurity                             77E26D81 5 Bytes  JMP 003E1014 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] ADVAPI32.dll!ChangeServiceConfigA                                 77E26E69 5 Bytes  JMP 003E0804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] ADVAPI32.dll!ChangeServiceConfigW                                 77E27001 5 Bytes  JMP 003E0A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] ADVAPI32.dll!ChangeServiceConfig2A                                77E27101 5 Bytes  JMP 003E0C0C 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] ADVAPI32.dll!ChangeServiceConfig2W                                77E27189 5 Bytes  JMP 003E0E10 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] ADVAPI32.dll!CreateServiceA                                       77E27211 5 Bytes  JMP 003E01F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] ADVAPI32.dll!CreateServiceW                                       77E273A9 5 Bytes  JMP 003E03FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] ADVAPI32.dll!DeleteService                                        77E274B1 5 Bytes  JMP 003E0600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] USER32.dll!SetWindowsHookExW                                      7E37820F 5 Bytes  JMP 003F0804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] USER32.dll!UnhookWindowsHookEx                                    7E37D5F3 5 Bytes  JMP 003F0A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] USER32.dll!SetWindowsHookExA                                      7E381211 5 Bytes  JMP 003F0600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] USER32.dll!SetWinEventHook                                        7E3817F7 5 Bytes  JMP 003F01F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2600] USER32.dll!UnhookWinEvent                                         7E3818AC 5 Bytes  JMP 003F03FC 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] ntdll.dll!LdrLoadDll                                                                                           7C91632D 5 Bytes  JMP 001501F8 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] ntdll.dll!RtlDosSearchPath_U + 186                                                                             7C916865 1 Byte  [62]
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] ntdll.dll!LdrUnloadDll                                                                                         7C9171CD 5 Bytes  JMP 001503FC 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] kernel32.dll!GetBinaryTypeW + 80                                                                               7C868D8C 1 Byte  [62]
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] USER32.dll!SetWindowsHookExW                                                                                   7E37820F 5 Bytes  JMP 003E0804 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] USER32.dll!UnhookWindowsHookEx                                                                                 7E37D5F3 5 Bytes  JMP 003E0A08 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] USER32.dll!SetWindowsHookExA                                                                                   7E381211 5 Bytes  JMP 003E0600 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] USER32.dll!SetWinEventHook                                                                                     7E3817F7 5 Bytes  JMP 003E01F8 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] USER32.dll!UnhookWinEvent                                                                                      7E3818AC 5 Bytes  JMP 003E03FC 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] ADVAPI32.dll!SetServiceObjectSecurity                                                                          77E26D81 5 Bytes  JMP 003F1014 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] ADVAPI32.dll!ChangeServiceConfigA                                                                              77E26E69 5 Bytes  JMP 003F0804 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] ADVAPI32.dll!ChangeServiceConfigW                                                                              77E27001 5 Bytes  JMP 003F0A08 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] ADVAPI32.dll!ChangeServiceConfig2A                                                                             77E27101 5 Bytes  JMP 003F0C0C 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] ADVAPI32.dll!ChangeServiceConfig2W                                                                             77E27189 5 Bytes  JMP 003F0E10 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] ADVAPI32.dll!CreateServiceA                                                                                    77E27211 5 Bytes  JMP 003F01F8 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] ADVAPI32.dll!CreateServiceW                                                                                    77E273A9 5 Bytes  JMP 003F03FC 
.text           C:\Program Files\TuneUp Utilities 2012\TUDefragBackend32.exe[2628] ADVAPI32.dll!DeleteService                                                                                     77E274B1 5 Bytes  JMP 003F0600 
.text           C:\WINDOWS\System32\alg.exe[2900] ntdll.dll!LdrLoadDll                                                                                                                            7C91632D 5 Bytes  JMP 000901F8 
.text           C:\WINDOWS\System32\alg.exe[2900] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                              7C916865 1 Byte  [62]
.text           C:\WINDOWS\System32\alg.exe[2900] ntdll.dll!LdrUnloadDll                                                                                                                          7C9171CD 5 Bytes  JMP 000903FC 
.text           C:\WINDOWS\System32\alg.exe[2900] kernel32.dll!GetBinaryTypeW + 80                                                                                                                7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\System32\alg.exe[2900] USER32.dll!SetWindowsHookExW                                                                                                                    7E37820F 5 Bytes  JMP 00300804 
.text           C:\WINDOWS\System32\alg.exe[2900] USER32.dll!UnhookWindowsHookEx                                                                                                                  7E37D5F3 5 Bytes  JMP 00300A08 
.text           C:\WINDOWS\System32\alg.exe[2900] USER32.dll!SetWindowsHookExA                                                                                                                    7E381211 5 Bytes  JMP 00300600 
.text           C:\WINDOWS\System32\alg.exe[2900] USER32.dll!SetWinEventHook                                                                                                                      7E3817F7 5 Bytes  JMP 003001F8 
.text           C:\WINDOWS\System32\alg.exe[2900] USER32.dll!UnhookWinEvent                                                                                                                       7E3818AC 5 Bytes  JMP 003003FC 
.text           C:\WINDOWS\System32\alg.exe[2900] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                           77E26D81 5 Bytes  JMP 00311014 
.text           C:\WINDOWS\System32\alg.exe[2900] ADVAPI32.dll!ChangeServiceConfigA                                                                                                               77E26E69 5 Bytes  JMP 00310804 
.text           C:\WINDOWS\System32\alg.exe[2900] ADVAPI32.dll!ChangeServiceConfigW                                                                                                               77E27001 5 Bytes  JMP 00310A08 
.text           C:\WINDOWS\System32\alg.exe[2900] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                              77E27101 5 Bytes  JMP 00310C0C 
.text           C:\WINDOWS\System32\alg.exe[2900] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                              77E27189 5 Bytes  JMP 00310E10 
.text           C:\WINDOWS\System32\alg.exe[2900] ADVAPI32.dll!CreateServiceA                                                                                                                     77E27211 5 Bytes  JMP 003101F8 
.text           C:\WINDOWS\System32\alg.exe[2900] ADVAPI32.dll!CreateServiceW                                                                                                                     77E273A9 5 Bytes  JMP 003103FC 
.text           C:\WINDOWS\System32\alg.exe[2900] ADVAPI32.dll!DeleteService                                                                                                                      77E274B1 5 Bytes  JMP 00310600 
.text           C:\WINDOWS\system32\svchost.exe[2988] ntdll.dll!LdrLoadDll                                                                                                                        7C91632D 5 Bytes  JMP 000901F8 
.text           C:\WINDOWS\system32\svchost.exe[2988] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                          7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[2988] ntdll.dll!LdrUnloadDll                                                                                                                      7C9171CD 5 Bytes  JMP 000903FC 
.text           C:\WINDOWS\system32\svchost.exe[2988] kernel32.dll!GetBinaryTypeW + 80                                                                                                            7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\svchost.exe[2988] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                       77E26D81 5 Bytes  JMP 00301014 
.text           C:\WINDOWS\system32\svchost.exe[2988] ADVAPI32.dll!ChangeServiceConfigA                                                                                                           77E26E69 5 Bytes  JMP 00300804 
.text           C:\WINDOWS\system32\svchost.exe[2988] ADVAPI32.dll!ChangeServiceConfigW                                                                                                           77E27001 5 Bytes  JMP 00300A08 
.text           C:\WINDOWS\system32\svchost.exe[2988] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                          77E27101 5 Bytes  JMP 00300C0C 
.text           C:\WINDOWS\system32\svchost.exe[2988] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                          77E27189 5 Bytes  JMP 00300E10 
.text           C:\WINDOWS\system32\svchost.exe[2988] ADVAPI32.dll!CreateServiceA                                                                                                                 77E27211 5 Bytes  JMP 003001F8 
.text           C:\WINDOWS\system32\svchost.exe[2988] ADVAPI32.dll!CreateServiceW                                                                                                                 77E273A9 5 Bytes  JMP 003003FC 
.text           C:\WINDOWS\system32\svchost.exe[2988] ADVAPI32.dll!DeleteService                                                                                                                  77E274B1 5 Bytes  JMP 00300600 
.text           C:\WINDOWS\system32\svchost.exe[2988] USER32.dll!SetWindowsHookExW                                                                                                                7E37820F 5 Bytes  JMP 00310804 
.text           C:\WINDOWS\system32\svchost.exe[2988] USER32.dll!UnhookWindowsHookEx                                                                                                              7E37D5F3 5 Bytes  JMP 00310A08 
.text           C:\WINDOWS\system32\svchost.exe[2988] USER32.dll!SetWindowsHookExA                                                                                                                7E381211 5 Bytes  JMP 00310600 
.text           C:\WINDOWS\system32\svchost.exe[2988] USER32.dll!SetWinEventHook                                                                                                                  7E3817F7 5 Bytes  JMP 003101F8 
.text           C:\WINDOWS\system32\svchost.exe[2988] USER32.dll!UnhookWinEvent                                                                                                                   7E3818AC 5 Bytes  JMP 003103FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtCreateFile + 6                                        7C90D0B4 4 Bytes  [28, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtCreateFile + B                                        7C90D0B9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 1 Byte  [28]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 4 Bytes  [28, 03, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtMapViewOfSection + B                                  7C90D529 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtOpenFile + 6                                          7C90D5A4 4 Bytes  [68, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtOpenFile + B                                          7C90D5A9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtOpenProcess + 6                                       7C90D604 4 Bytes  [A8, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtOpenProcess + B                                       7C90D609 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtOpenProcessToken + 6                                  7C90D614 4 Bytes  CALL 7B90EC1A 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtOpenProcessToken + B                                  7C90D619 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtOpenProcessTokenEx + 6                                7C90D624 4 Bytes  [A8, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtOpenProcessTokenEx + B                                7C90D629 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtOpenThread + 6                                        7C90D664 4 Bytes  [68, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtOpenThread + B                                        7C90D669 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtOpenThreadToken + 6                                   7C90D674 4 Bytes  [68, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtOpenThreadToken + B                                   7C90D679 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtOpenThreadTokenEx + 6                                 7C90D684 4 Bytes  CALL 7B90EC8B 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtOpenThreadTokenEx + B                                 7C90D689 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtQueryAttributesFile + 6                               7C90D714 4 Bytes  [A8, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtQueryAttributesFile + B                               7C90D719 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtQueryFullAttributesFile + 6                           7C90D7B4 4 Bytes  CALL 7B90EDB9 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtQueryFullAttributesFile + B                           7C90D7B9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtSetInformationFile + 6                                7C90DC64 4 Bytes  [28, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtSetInformationFile + B                                7C90DC69 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtSetInformationThread + 6                              7C90DCB4 4 Bytes  [28, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtSetInformationThread + B                              7C90DCB9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 1 Byte  [68]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 4 Bytes  [68, 03, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!NtUnmapViewOfSection + B                                7C90DF19 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!LdrLoadDll                                              7C91632D 5 Bytes  JMP 001801F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!RtlDosSearchPath_U + 186                                7C916865 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ntdll.dll!LdrUnloadDll                                            7C9171CD 5 Bytes  JMP 001803FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] kernel32.dll!GetBinaryTypeW + 80                                  7C868D8C 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ADVAPI32.dll!SetServiceObjectSecurity                             77E26D81 5 Bytes  JMP 00571014 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ADVAPI32.dll!ChangeServiceConfigA                                 77E26E69 5 Bytes  JMP 00570804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ADVAPI32.dll!ChangeServiceConfigW                                 77E27001 5 Bytes  JMP 00570A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ADVAPI32.dll!ChangeServiceConfig2A                                77E27101 5 Bytes  JMP 00570C0C 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ADVAPI32.dll!ChangeServiceConfig2W                                77E27189 5 Bytes  JMP 00570E10 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ADVAPI32.dll!CreateServiceA                                       77E27211 5 Bytes  JMP 005701F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ADVAPI32.dll!CreateServiceW                                       77E273A9 5 Bytes  JMP 005703FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] ADVAPI32.dll!DeleteService                                        77E274B1 5 Bytes  JMP 00570600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] USER32.dll!SetWindowsHookExW                                      7E37820F 5 Bytes  JMP 00580804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] USER32.dll!UnhookWindowsHookEx                                    7E37D5F3 5 Bytes  JMP 00580A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] USER32.dll!SetWindowsHookExA                                      7E381211 5 Bytes  JMP 00580600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] USER32.dll!SetWinEventHook                                        7E3817F7 5 Bytes  JMP 005801F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] USER32.dll!UnhookWinEvent                                         7E3818AC 5 Bytes  JMP 005803FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtCreateFile + 6                                        7C90D0B4 4 Bytes  [28, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtCreateFile + B                                        7C90D0B9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 1 Byte  [28]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 4 Bytes  [28, 03, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtMapViewOfSection + B                                  7C90D529 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtOpenFile + 6                                          7C90D5A4 4 Bytes  [68, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtOpenFile + B                                          7C90D5A9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtOpenProcess + 6                                       7C90D604 4 Bytes  [A8, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtOpenProcess + B                                       7C90D609 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtOpenProcessToken + 6                                  7C90D614 4 Bytes  CALL 7B90EC1A 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtOpenProcessToken + B                                  7C90D619 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtOpenProcessTokenEx + 6                                7C90D624 4 Bytes  [A8, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtOpenProcessTokenEx + B                                7C90D629 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtOpenThread + 6                                        7C90D664 4 Bytes  [68, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtOpenThread + B                                        7C90D669 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtOpenThreadToken + 6                                   7C90D674 4 Bytes  [68, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtOpenThreadToken + B                                   7C90D679 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtOpenThreadTokenEx + 6                                 7C90D684 4 Bytes  CALL 7B90EC8B 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtOpenThreadTokenEx + B                                 7C90D689 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtQueryAttributesFile + 6                               7C90D714 4 Bytes  [A8, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtQueryAttributesFile + B                               7C90D719 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtQueryFullAttributesFile + 6                           7C90D7B4 4 Bytes  CALL 7B90EDB9 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtQueryFullAttributesFile + B                           7C90D7B9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtSetInformationFile + 6                                7C90DC64 4 Bytes  [28, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtSetInformationFile + B                                7C90DC69 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtSetInformationThread + 6                              7C90DCB4 4 Bytes  [28, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtSetInformationThread + B                              7C90DCB9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 1 Byte  [68]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 4 Bytes  [68, 03, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!NtUnmapViewOfSection + B                                7C90DF19 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!LdrLoadDll                                              7C91632D 5 Bytes  JMP 001801F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!RtlDosSearchPath_U + 186                                7C916865 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ntdll.dll!LdrUnloadDll                                            7C9171CD 5 Bytes  JMP 001803FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] kernel32.dll!GetBinaryTypeW + 80                                  7C868D8C 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ADVAPI32.dll!SetServiceObjectSecurity                             77E26D81 5 Bytes  JMP 00571014 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ADVAPI32.dll!ChangeServiceConfigA                                 77E26E69 5 Bytes  JMP 00570804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ADVAPI32.dll!ChangeServiceConfigW                                 77E27001 5 Bytes  JMP 00570A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ADVAPI32.dll!ChangeServiceConfig2A                                77E27101 5 Bytes  JMP 00570C0C 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ADVAPI32.dll!ChangeServiceConfig2W                                77E27189 5 Bytes  JMP 00570E10 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ADVAPI32.dll!CreateServiceA                                       77E27211 5 Bytes  JMP 005701F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ADVAPI32.dll!CreateServiceW                                       77E273A9 5 Bytes  JMP 005703FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] ADVAPI32.dll!DeleteService                                        77E274B1 5 Bytes  JMP 00570600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] USER32.dll!SetWindowsHookExW                                      7E37820F 5 Bytes  JMP 00580804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] USER32.dll!UnhookWindowsHookEx                                    7E37D5F3 5 Bytes  JMP 00580A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] USER32.dll!SetWindowsHookExA                                      7E381211 5 Bytes  JMP 00580600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] USER32.dll!SetWinEventHook                                        7E3817F7 5 Bytes  JMP 005801F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] USER32.dll!UnhookWinEvent                                         7E3818AC 5 Bytes  JMP 005803FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtCreateFile + 6                                        7C90D0B4 4 Bytes  [28, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtCreateFile + B                                        7C90D0B9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 1 Byte  [28]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 4 Bytes  [28, 03, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtMapViewOfSection + B                                  7C90D529 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtOpenFile + 6                                          7C90D5A4 4 Bytes  [68, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtOpenFile + B                                          7C90D5A9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtOpenProcess + 6                                       7C90D604 4 Bytes  [A8, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtOpenProcess + B                                       7C90D609 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtOpenProcessToken + 6                                  7C90D614 4 Bytes  CALL 7B90EC1A 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtOpenProcessToken + B                                  7C90D619 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtOpenProcessTokenEx + 6                                7C90D624 4 Bytes  [A8, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtOpenProcessTokenEx + B                                7C90D629 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtOpenThread + 6                                        7C90D664 4 Bytes  [68, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtOpenThread + B                                        7C90D669 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtOpenThreadToken + 6                                   7C90D674 4 Bytes  [68, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtOpenThreadToken + B                                   7C90D679 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtOpenThreadTokenEx + 6                                 7C90D684 4 Bytes  CALL 7B90EC8B 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtOpenThreadTokenEx + B                                 7C90D689 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtQueryAttributesFile + 6                               7C90D714 4 Bytes  [A8, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtQueryAttributesFile + B                               7C90D719 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtQueryFullAttributesFile + 6                           7C90D7B4 4 Bytes  CALL 7B90EDB9 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtQueryFullAttributesFile + B                           7C90D7B9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtSetInformationFile + 6                                7C90DC64 4 Bytes  [28, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtSetInformationFile + B                                7C90DC69 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtSetInformationThread + 6                              7C90DCB4 4 Bytes  [28, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtSetInformationThread + B                              7C90DCB9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 1 Byte  [68]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 4 Bytes  [68, 03, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!NtUnmapViewOfSection + B                                7C90DF19 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!LdrLoadDll                                              7C91632D 5 Bytes  JMP 001801F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!RtlDosSearchPath_U + 186                                7C916865 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ntdll.dll!LdrUnloadDll                                            7C9171CD 5 Bytes  JMP 001803FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] kernel32.dll!GetBinaryTypeW + 80                                  7C868D8C 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ADVAPI32.dll!SetServiceObjectSecurity                             77E26D81 5 Bytes  JMP 00571014 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ADVAPI32.dll!ChangeServiceConfigA                                 77E26E69 5 Bytes  JMP 00570804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ADVAPI32.dll!ChangeServiceConfigW                                 77E27001 5 Bytes  JMP 00570A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ADVAPI32.dll!ChangeServiceConfig2A                                77E27101 5 Bytes  JMP 00570C0C 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ADVAPI32.dll!ChangeServiceConfig2W                                77E27189 5 Bytes  JMP 00570E10 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ADVAPI32.dll!CreateServiceA                                       77E27211 5 Bytes  JMP 005701F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ADVAPI32.dll!CreateServiceW                                       77E273A9 5 Bytes  JMP 005703FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] ADVAPI32.dll!DeleteService                                        77E274B1 5 Bytes  JMP 00570600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] USER32.dll!SetWindowsHookExW                                      7E37820F 5 Bytes  JMP 00580804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] USER32.dll!UnhookWindowsHookEx                                    7E37D5F3 5 Bytes  JMP 00580A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] USER32.dll!SetWindowsHookExA                                      7E381211 5 Bytes  JMP 00580600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] USER32.dll!SetWinEventHook                                        7E3817F7 5 Bytes  JMP 005801F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] USER32.dll!UnhookWinEvent                                         7E3818AC 5 Bytes  JMP 005803FC 
.text           C:\WINDOWS\System32\svchost.exe[3476] ntdll.dll!LdrLoadDll                                                                                                                        7C91632D 5 Bytes  JMP 000901F8 
.text           C:\WINDOWS\System32\svchost.exe[3476] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                          7C916865 1 Byte  [62]
.text           C:\WINDOWS\System32\svchost.exe[3476] ntdll.dll!LdrUnloadDll                                                                                                                      7C9171CD 5 Bytes  JMP 000903FC 
.text           C:\WINDOWS\System32\svchost.exe[3476] kernel32.dll!GetBinaryTypeW + 80                                                                                                            7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\System32\svchost.exe[3476] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                       77E26D81 5 Bytes  JMP 00301014 
.text           C:\WINDOWS\System32\svchost.exe[3476] ADVAPI32.dll!ChangeServiceConfigA                                                                                                           77E26E69 5 Bytes  JMP 00300804 
.text           C:\WINDOWS\System32\svchost.exe[3476] ADVAPI32.dll!ChangeServiceConfigW                                                                                                           77E27001 5 Bytes  JMP 00300A08 
.text           C:\WINDOWS\System32\svchost.exe[3476] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                          77E27101 5 Bytes  JMP 00300C0C 
.text           C:\WINDOWS\System32\svchost.exe[3476] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                          77E27189 5 Bytes  JMP 00300E10 
.text           C:\WINDOWS\System32\svchost.exe[3476] ADVAPI32.dll!CreateServiceA                                                                                                                 77E27211 5 Bytes  JMP 003001F8 
.text           C:\WINDOWS\System32\svchost.exe[3476] ADVAPI32.dll!CreateServiceW                                                                                                                 77E273A9 5 Bytes  JMP 003003FC 
.text           C:\WINDOWS\System32\svchost.exe[3476] ADVAPI32.dll!DeleteService                                                                                                                  77E274B1 5 Bytes  JMP 00300600 
.text           C:\WINDOWS\System32\svchost.exe[3476] USER32.dll!SetWindowsHookExW                                                                                                                7E37820F 5 Bytes  JMP 00310804 
.text           C:\WINDOWS\System32\svchost.exe[3476] USER32.dll!UnhookWindowsHookEx                                                                                                              7E37D5F3 5 Bytes  JMP 00310A08 
.text           C:\WINDOWS\System32\svchost.exe[3476] USER32.dll!SetWindowsHookExA                                                                                                                7E381211 5 Bytes  JMP 00310600 
.text           C:\WINDOWS\System32\svchost.exe[3476] USER32.dll!SetWinEventHook                                                                                                                  7E3817F7 5 Bytes  JMP 003101F8 
.text           C:\WINDOWS\System32\svchost.exe[3476] USER32.dll!UnhookWinEvent                                                                                                                   7E3818AC 5 Bytes  JMP 003103FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtCreateFile + 6                                        7C90D0B4 4 Bytes  [28, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtCreateFile + B                                        7C90D0B9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 1 Byte  [28]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtMapViewOfSection + 6                                  7C90D524 4 Bytes  [28, 03, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtMapViewOfSection + B                                  7C90D529 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtOpenFile + 6                                          7C90D5A4 4 Bytes  [68, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtOpenFile + B                                          7C90D5A9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtOpenProcess + 6                                       7C90D604 4 Bytes  [A8, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtOpenProcess + B                                       7C90D609 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtOpenProcessToken + 6                                  7C90D614 4 Bytes  CALL 7B90EC1A 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtOpenProcessToken + B                                  7C90D619 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtOpenProcessTokenEx + 6                                7C90D624 4 Bytes  [A8, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtOpenProcessTokenEx + B                                7C90D629 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtOpenThread + 6                                        7C90D664 4 Bytes  [68, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtOpenThread + B                                        7C90D669 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtOpenThreadToken + 6                                   7C90D674 4 Bytes  [68, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtOpenThreadToken + B                                   7C90D679 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtOpenThreadTokenEx + 6                                 7C90D684 4 Bytes  CALL 7B90EC8B 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtOpenThreadTokenEx + B                                 7C90D689 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtQueryAttributesFile + 6                               7C90D714 4 Bytes  [A8, 00, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtQueryAttributesFile + B                               7C90D719 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtQueryFullAttributesFile + 6                           7C90D7B4 4 Bytes  CALL 7B90EDB9 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtQueryFullAttributesFile + B                           7C90D7B9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtSetInformationFile + 6                                7C90DC64 4 Bytes  [28, 01, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtSetInformationFile + B                                7C90DC69 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtSetInformationThread + 6                              7C90DCB4 4 Bytes  [28, 02, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtSetInformationThread + B                              7C90DCB9 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 1 Byte  [68]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtUnmapViewOfSection + 6                                7C90DF14 4 Bytes  [68, 03, 16, 00]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!NtUnmapViewOfSection + B                                7C90DF19 1 Byte  [E2]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!LdrLoadDll                                              7C91632D 5 Bytes  JMP 001801F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!RtlDosSearchPath_U + 186                                7C916865 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ntdll.dll!LdrUnloadDll                                            7C9171CD 5 Bytes  JMP 001803FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] kernel32.dll!GetBinaryTypeW + 80                                  7C868D8C 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ADVAPI32.dll!SetServiceObjectSecurity                             77E26D81 5 Bytes  JMP 00571014 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ADVAPI32.dll!ChangeServiceConfigA                                 77E26E69 5 Bytes  JMP 00570804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ADVAPI32.dll!ChangeServiceConfigW                                 77E27001 5 Bytes  JMP 00570A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ADVAPI32.dll!ChangeServiceConfig2A                                77E27101 5 Bytes  JMP 00570C0C 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ADVAPI32.dll!ChangeServiceConfig2W                                77E27189 5 Bytes  JMP 00570E10 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ADVAPI32.dll!CreateServiceA                                       77E27211 5 Bytes  JMP 005701F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ADVAPI32.dll!CreateServiceW                                       77E273A9 5 Bytes  JMP 005703FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] ADVAPI32.dll!DeleteService                                        77E274B1 5 Bytes  JMP 00570600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] USER32.dll!SetWindowsHookExW                                      7E37820F 5 Bytes  JMP 00580804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] USER32.dll!UnhookWindowsHookEx                                    7E37D5F3 5 Bytes  JMP 00580A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] USER32.dll!SetWindowsHookExA                                      7E381211 5 Bytes  JMP 00580600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] USER32.dll!SetWinEventHook                                        7E3817F7 5 Bytes  JMP 005801F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] USER32.dll!UnhookWinEvent                                         7E3818AC 5 Bytes  JMP 005803FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!LdrLoadDll                                              7C91632D 5 Bytes  JMP 001501F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!RtlDosSearchPath_U + 186                                7C916865 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] ntdll.dll!LdrUnloadDll                                            7C9171CD 5 Bytes  JMP 001503FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] kernel32.dll!GetBinaryTypeW + 80                                  7C868D8C 1 Byte  [62]
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!SetServiceObjectSecurity                             77E26D81 5 Bytes  JMP 003E1014 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!ChangeServiceConfigA                                 77E26E69 5 Bytes  JMP 003E0804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!ChangeServiceConfigW                                 77E27001 5 Bytes  JMP 003E0A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!ChangeServiceConfig2A                                77E27101 5 Bytes  JMP 003E0C0C 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!ChangeServiceConfig2W                                77E27189 5 Bytes  JMP 003E0E10 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!CreateServiceA                                       77E27211 5 Bytes  JMP 003E01F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!CreateServiceW                                       77E273A9 5 Bytes  JMP 003E03FC 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] ADVAPI32.dll!DeleteService                                        77E274B1 5 Bytes  JMP 003E0600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] USER32.dll!SetWindowsHookExW                                      7E37820F 5 Bytes  JMP 003F0804 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] USER32.dll!UnhookWindowsHookEx                                    7E37D5F3 5 Bytes  JMP 003F0A08 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] USER32.dll!SetWindowsHookExA                                      7E381211 5 Bytes  JMP 003F0600 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] USER32.dll!SetWinEventHook                                        7E3817F7 5 Bytes  JMP 003F01F8 
.text           C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3632] USER32.dll!UnhookWinEvent                                         7E3818AC 5 Bytes  JMP 003F03FC 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] ntdll.dll!LdrLoadDll                                                                                                                        7C91632D 5 Bytes  JMP 000901F8 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] ntdll.dll!RtlDosSearchPath_U + 186                                                                                                          7C916865 1 Byte  [62]
.text           C:\WINDOWS\system32\wscntfy.exe[4092] ntdll.dll!LdrUnloadDll                                                                                                                      7C9171CD 5 Bytes  JMP 000903FC 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] kernel32.dll!GetBinaryTypeW + 80                                                                                                            7C868D8C 1 Byte  [62]
.text           C:\WINDOWS\system32\wscntfy.exe[4092] USER32.dll!SetWindowsHookExW                                                                                                                7E37820F 5 Bytes  JMP 00320804 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] USER32.dll!UnhookWindowsHookEx                                                                                                              7E37D5F3 5 Bytes  JMP 00320A08 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] USER32.dll!SetWindowsHookExA                                                                                                                7E381211 5 Bytes  JMP 00320600 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] USER32.dll!SetWinEventHook                                                                                                                  7E3817F7 5 Bytes  JMP 003201F8 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] USER32.dll!UnhookWinEvent                                                                                                                   7E3818AC 5 Bytes  JMP 003203FC 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] ADVAPI32.dll!SetServiceObjectSecurity                                                                                                       77E26D81 5 Bytes  JMP 00331014 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] ADVAPI32.dll!ChangeServiceConfigA                                                                                                           77E26E69 5 Bytes  JMP 00330804 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] ADVAPI32.dll!ChangeServiceConfigW                                                                                                           77E27001 5 Bytes  JMP 00330A08 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] ADVAPI32.dll!ChangeServiceConfig2A                                                                                                          77E27101 5 Bytes  JMP 00330C0C 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] ADVAPI32.dll!ChangeServiceConfig2W                                                                                                          77E27189 5 Bytes  JMP 00330E10 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] ADVAPI32.dll!CreateServiceA                                                                                                                 77E27211 5 Bytes  JMP 003301F8 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] ADVAPI32.dll!CreateServiceW                                                                                                                 77E273A9 5 Bytes  JMP 003303FC 
.text           C:\WINDOWS\system32\wscntfy.exe[4092] ADVAPI32.dll!DeleteService                                                                                                                  77E274B1 5 Bytes  JMP 00330600 

---- User IAT/EAT - GMER 1.0.15 ----

IAT             C:\Program Files\AVAST Software\Avast\avastUI.exe[152] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                                                             [64C8F6A0] C:\Program Files\AVAST Software\Avast\aswCmnBS.dll (Common functions/AVAST Software)
IAT             C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[952] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW]   002E0010
IAT             C:\WINDOWS\system32\services.exe[1088] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW]                                                                     00630002
IAT             C:\WINDOWS\system32\services.exe[1088] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW]                                                                           00630000
IAT             C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1744] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                                                           [64C8F6A0] C:\Program Files\AVAST Software\Avast\aswCmnBS.dll (Common functions/AVAST Software)
IAT             C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[1976] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW]  002A0010
IAT             C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[2444] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW]  002A0010
IAT             C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3048] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW]  002E0010
IAT             C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3120] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW]  002F0010
IAT             C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3316] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW]  002A0010
IAT             C:\Documents and Settings\Gr2eg0rz\Ustawienia lokalne\Dane aplikacji\Google\Chrome\Application\chrome.exe[3556] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW]  002E0010

---- Devices - GMER 1.0.15 ----

Device          \FileSystem\Ntfs \Ntfs                                                                                                                                                            aswSP.SYS (avast! self protection module/AVAST Software)

AttachedDevice  \FileSystem\Ntfs \Ntfs                                                                                                                                                            aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)
AttachedDevice  \Driver\Tcpip \Device\Ip                                                                                                                                                          aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice  \Driver\Tcpip \Device\Tcp                                                                                                                                                         aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice  \Driver\Tcpip \Device\Udp                                                                                                                                                         aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice  \Driver\Tcpip \Device\RawIp                                                                                                                                                       aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

---- EOF - GMER 1.0.15 ----
