GMER 1.0.15.15641 - http://www.gmer.net Rootkit scan 2012-02-10 20:03:11 Windows 5.1.2600 Dodatek Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST9320325AS rev.0002SDM1 Running: z7hvp34e.exe; Driver: C:\DOCUME~1\Jan\USTAWI~1\Temp\kwdyapob.sys ---- System - GMER 1.0.15 ---- SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwAddBootEntry [0xA7EEF9CA] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwAllocateVirtualMemory [0xA7F44A68] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwClose [0xA7F0FAF5] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEvent [0xA7EF1EAC] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateEventPair [0xA7EF1F04] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateIoCompletion [0xA7EF201A] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateKey [0xA7F0F4A9] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateMutant [0xA7EF1E02] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSection [0xA7EF1F54] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateSemaphore [0xA7EF1E56] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwCreateTimer [0xA7EF1FC8] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteBootEntry [0xA7EEF9EE] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteKey [0xA7F101BB] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDeleteValueKey [0xA7F10471] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwDuplicateObject [0xA7EF229E] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateKey [0xA7F10026] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwEnumerateValueKey [0xA7F0FE91] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwFreeVirtualMemory [0xA7F44B18] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwLoadDriver [0xA7EEF7B8] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwModifyBootEntry [0xA7EEFA12] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeKey [0xA7EF2412] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwNotifyChangeMultipleKeys [0xA7EF04AA] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEvent [0xA7EF1EDC] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenEventPair [0xA7EF1F2C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenIoCompletion [0xA7EF2044] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenKey [0xA7F0F805] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenMutant [0xA7EF1E2E] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenProcess [0xA7EF20D6] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSection [0xA7EF1F94] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenSemaphore [0xA7EF1E84] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenThread [0xA7EF21BA] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwOpenTimer [0xA7EF1FF2] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwProtectVirtualMemory [0xA7F44BB0] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryKey [0xA7F0FD0C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryObject [0xA7EF0370] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwQueryValueKey [0xA7F0FB5E] SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwRenameKey [0xA7F4CE26] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwRestoreKey [0xA7F0EB1C] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootEntryOrder [0xA7EEFA36] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetBootOptions [0xA7EEFA5A] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemInformation [0xA7EEF812] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetSystemPowerState [0xA7EEF94E] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSetValueKey [0xA7F102C2] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwShutdownSystem [0xA7EEF92A] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwSystemDebugControl [0xA7EEF972] SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess [0xB9F42812] SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) ZwVdmControl [0xA7EEFA7E] Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0xA7F598DE] Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject ---- Kernel code sections - GMER 1.0.15 ---- PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 5EC 805A648C 4 Bytes CALL A7EF0E25 \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/AVAST Software) PAGE ntkrnlpa.exe!ObMakeTemporaryObject 805BC512 5 Bytes JMP A7F5529E \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) PAGE ntkrnlpa.exe!ObInsertObject 805C2F96 5 Bytes JMP A7F56D38 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) PAGE ntkrnlpa.exe!ZwCreateProcessEx 805D1136 7 Bytes JMP A7F598E2 \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) init C:\WINDOWS\system32\drivers\monfilt.sys entry point in "init" section [0xA849A280] .text C:\WINDOWS\system32\DRIVERS\atksgt.sys section is writeable [0xA77C1300, 0x3AE88, 0xE8000020] .text C:\WINDOWS\system32\DRIVERS\lirsgt.sys section is writeable [0xB9BA0300, 0x1B7E, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text C:\WINDOWS\system32\spoolsv.exe[240] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\system32\spoolsv.exe[240] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\system32\spoolsv.exe[240] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003001D4 .text C:\WINDOWS\system32\spoolsv.exe[240] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003000E4 .text C:\WINDOWS\system32\spoolsv.exe[240] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00300120 .text C:\WINDOWS\system32\spoolsv.exe[240] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0030015C .text C:\WINDOWS\system32\spoolsv.exe[240] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00300198 .text C:\WINDOWS\system32\spoolsv.exe[240] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00300030 .text C:\WINDOWS\system32\spoolsv.exe[240] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0030006C .text C:\WINDOWS\system32\spoolsv.exe[240] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003000A8 .text C:\WINDOWS\system32\spoolsv.exe[240] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003100E4 .text C:\WINDOWS\system32\spoolsv.exe[240] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310120 .text C:\WINDOWS\system32\spoolsv.exe[240] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003100A8 .text C:\WINDOWS\system32\spoolsv.exe[240] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00310030 .text C:\WINDOWS\system32\spoolsv.exe[240] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0031006C .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 004F01D4 .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 004F00E4 .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 004F0120 .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 004F015C .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 004F0198 .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 004F0030 .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 004F006C .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 004F00A8 .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 005000E4 .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00500120 .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 005000A8 .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00500030 .text C:\Program Files\ASUS\Splendid\ACMON.exe[248] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0050006C .text C:\Program Files\Elantech\ETDCtrl.exe[260] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Elantech\ETDCtrl.exe[260] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Elantech\ETDCtrl.exe[260] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\Program Files\Elantech\ETDCtrl.exe[260] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\Program Files\Elantech\ETDCtrl.exe[260] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\Program Files\Elantech\ETDCtrl.exe[260] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\Program Files\Elantech\ETDCtrl.exe[260] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\Program Files\Elantech\ETDCtrl.exe[260] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\Program Files\Elantech\ETDCtrl.exe[260] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\Program Files\Elantech\ETDCtrl.exe[260] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\Program Files\Elantech\ETDCtrl.exe[260] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003F00E4 .text C:\Program Files\Elantech\ETDCtrl.exe[260] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003F0120 .text C:\Program Files\Elantech\ETDCtrl.exe[260] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003F00A8 .text C:\Program Files\Elantech\ETDCtrl.exe[260] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003F0030 .text C:\Program Files\Elantech\ETDCtrl.exe[260] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003F006C .text C:\Program Files\Winamp\winampa.exe[324] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00080030 .text C:\Program Files\Winamp\winampa.exe[324] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0008006C .text C:\Program Files\Winamp\winampa.exe[324] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003201D4 .text C:\Program Files\Winamp\winampa.exe[324] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003200E4 .text C:\Program Files\Winamp\winampa.exe[324] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00320120 .text C:\Program Files\Winamp\winampa.exe[324] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0032015C .text C:\Program Files\Winamp\winampa.exe[324] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00320198 .text C:\Program Files\Winamp\winampa.exe[324] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00320030 .text C:\Program Files\Winamp\winampa.exe[324] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0032006C .text C:\Program Files\Winamp\winampa.exe[324] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003200A8 .text C:\Program Files\Winamp\winampa.exe[324] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003300E4 .text C:\Program Files\Winamp\winampa.exe[324] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00330120 .text C:\Program Files\Winamp\winampa.exe[324] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003300A8 .text C:\Program Files\Winamp\winampa.exe[324] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00330030 .text C:\Program Files\Winamp\winampa.exe[324] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0033006C .text C:\Program Files\Java\jre6\bin\jusched.exe[536] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Java\jre6\bin\jusched.exe[536] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Java\jre6\bin\jusched.exe[536] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\Program Files\Java\jre6\bin\jusched.exe[536] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\Program Files\Java\jre6\bin\jusched.exe[536] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\Program Files\Java\jre6\bin\jusched.exe[536] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\Program Files\Java\jre6\bin\jusched.exe[536] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\Program Files\Java\jre6\bin\jusched.exe[536] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\Program Files\Java\jre6\bin\jusched.exe[536] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\Program Files\Java\jre6\bin\jusched.exe[536] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\Program Files\Java\jre6\bin\jusched.exe[536] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003F00E4 .text C:\Program Files\Java\jre6\bin\jusched.exe[536] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003F0120 .text C:\Program Files\Java\jre6\bin\jusched.exe[536] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003F00A8 .text C:\Program Files\Java\jre6\bin\jusched.exe[536] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003F0030 .text C:\Program Files\Java\jre6\bin\jusched.exe[536] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003F006C .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003F00E4 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003F0120 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003F00A8 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003F0030 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe[552] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003F006C .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00140030 .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0014006C .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003F00E4 .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003F0120 .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003F00A8 .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003F0030 .text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[580] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003F006C .text C:\WINDOWS\system32\ACEngSvr.exe[592] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00140030 .text C:\WINDOWS\system32\ACEngSvr.exe[592] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0014006C .text C:\WINDOWS\system32\ACEngSvr.exe[592] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003D01D4 .text C:\WINDOWS\system32\ACEngSvr.exe[592] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003D00E4 .text C:\WINDOWS\system32\ACEngSvr.exe[592] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003D0120 .text C:\WINDOWS\system32\ACEngSvr.exe[592] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003D015C .text C:\WINDOWS\system32\ACEngSvr.exe[592] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003D0198 .text C:\WINDOWS\system32\ACEngSvr.exe[592] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003D0030 .text C:\WINDOWS\system32\ACEngSvr.exe[592] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003D006C .text C:\WINDOWS\system32\ACEngSvr.exe[592] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003D00A8 .text C:\WINDOWS\system32\ACEngSvr.exe[592] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\WINDOWS\system32\ACEngSvr.exe[592] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\WINDOWS\system32\ACEngSvr.exe[592] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\WINDOWS\system32\ACEngSvr.exe[592] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\WINDOWS\system32\ACEngSvr.exe[592] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 004E00E4 .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 004E0120 .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 004E00A8 .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 004E0030 .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 004E006C .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 004F01D4 .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 004F00E4 .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 004F0120 .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 004F015C .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 004F0198 .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 004F0030 .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 004F006C .text C:\Program Files\Common Files\ABBYY\FineReader\10.00\Licensing\PE\NetworkLicenseServer.exe[764] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 004F00A8 .text C:\WINDOWS\System32\svchost.exe[800] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\System32\svchost.exe[800] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\System32\svchost.exe[800] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003001D4 .text C:\WINDOWS\System32\svchost.exe[800] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003000E4 .text C:\WINDOWS\System32\svchost.exe[800] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00300120 .text C:\WINDOWS\System32\svchost.exe[800] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0030015C .text C:\WINDOWS\System32\svchost.exe[800] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00300198 .text C:\WINDOWS\System32\svchost.exe[800] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00300030 .text C:\WINDOWS\System32\svchost.exe[800] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0030006C .text C:\WINDOWS\System32\svchost.exe[800] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003000A8 .text C:\WINDOWS\System32\svchost.exe[800] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003100E4 .text C:\WINDOWS\System32\svchost.exe[800] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310120 .text C:\WINDOWS\System32\svchost.exe[800] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003100A8 .text C:\WINDOWS\System32\svchost.exe[800] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00310030 .text C:\WINDOWS\System32\svchost.exe[800] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0031006C .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00140030 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0014006C .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003D01D4 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003D00E4 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003D0120 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003D015C .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003D0198 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003D0030 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003D006C .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003D00A8 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe[804] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\WINDOWS\system32\winlogon.exe[868] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00070030 .text C:\WINDOWS\system32\winlogon.exe[868] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0007006C .text C:\WINDOWS\system32\winlogon.exe[868] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003001D4 .text C:\WINDOWS\system32\winlogon.exe[868] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003000E4 .text C:\WINDOWS\system32\winlogon.exe[868] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00300120 .text C:\WINDOWS\system32\winlogon.exe[868] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0030015C .text C:\WINDOWS\system32\winlogon.exe[868] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00300198 .text C:\WINDOWS\system32\winlogon.exe[868] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00300030 .text C:\WINDOWS\system32\winlogon.exe[868] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0030006C .text C:\WINDOWS\system32\winlogon.exe[868] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003000A8 .text C:\WINDOWS\system32\winlogon.exe[868] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003100E4 .text C:\WINDOWS\system32\winlogon.exe[868] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310120 .text C:\WINDOWS\system32\winlogon.exe[868] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003100A8 .text C:\WINDOWS\system32\winlogon.exe[868] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00310030 .text C:\WINDOWS\system32\winlogon.exe[868] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0031006C .text C:\WINDOWS\system32\services.exe[912] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\system32\services.exe[912] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\system32\services.exe[912] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003001D4 .text C:\WINDOWS\system32\services.exe[912] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003000E4 .text C:\WINDOWS\system32\services.exe[912] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00300120 .text C:\WINDOWS\system32\services.exe[912] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0030015C .text C:\WINDOWS\system32\services.exe[912] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00300198 .text C:\WINDOWS\system32\services.exe[912] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00300030 .text C:\WINDOWS\system32\services.exe[912] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0030006C .text C:\WINDOWS\system32\services.exe[912] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003000A8 .text C:\WINDOWS\system32\services.exe[912] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003100E4 .text C:\WINDOWS\system32\services.exe[912] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310120 .text C:\WINDOWS\system32\services.exe[912] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003100A8 .text C:\WINDOWS\system32\services.exe[912] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00310030 .text C:\WINDOWS\system32\services.exe[912] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0031006C .text C:\WINDOWS\system32\lsass.exe[948] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\system32\lsass.exe[948] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003001D4 .text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003000E4 .text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00300120 .text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0030015C .text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00300198 .text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00300030 .text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0030006C .text C:\WINDOWS\system32\lsass.exe[948] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003000A8 .text C:\WINDOWS\system32\lsass.exe[948] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003100E4 .text C:\WINDOWS\system32\lsass.exe[948] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310120 .text C:\WINDOWS\system32\lsass.exe[948] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003100A8 .text C:\WINDOWS\system32\lsass.exe[948] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00310030 .text C:\WINDOWS\system32\lsass.exe[948] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0031006C .text C:\WINDOWS\system32\svchost.exe[1084] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\system32\svchost.exe[1084] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\system32\svchost.exe[1084] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003001D4 .text C:\WINDOWS\system32\svchost.exe[1084] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003000E4 .text C:\WINDOWS\system32\svchost.exe[1084] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00300120 .text C:\WINDOWS\system32\svchost.exe[1084] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0030015C .text C:\WINDOWS\system32\svchost.exe[1084] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00300198 .text C:\WINDOWS\system32\svchost.exe[1084] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00300030 .text C:\WINDOWS\system32\svchost.exe[1084] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0030006C .text C:\WINDOWS\system32\svchost.exe[1084] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003000A8 .text C:\WINDOWS\system32\svchost.exe[1084] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003100E4 .text C:\WINDOWS\system32\svchost.exe[1084] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310120 .text C:\WINDOWS\system32\svchost.exe[1084] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003100A8 .text C:\WINDOWS\system32\svchost.exe[1084] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00310030 .text C:\WINDOWS\system32\svchost.exe[1084] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0031006C .text C:\WINDOWS\system32\svchost.exe[1144] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\system32\svchost.exe[1144] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003001D4 .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003000E4 .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00300120 .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0030015C .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00300198 .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00300030 .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0030006C .text C:\WINDOWS\system32\svchost.exe[1144] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003000A8 .text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003100E4 .text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310120 .text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003100A8 .text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00310030 .text C:\WINDOWS\system32\svchost.exe[1144] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0031006C .text C:\WINDOWS\System32\svchost.exe[1184] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\System32\svchost.exe[1184] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\System32\svchost.exe[1184] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003001D4 .text C:\WINDOWS\System32\svchost.exe[1184] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003000E4 .text C:\WINDOWS\System32\svchost.exe[1184] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00300120 .text C:\WINDOWS\System32\svchost.exe[1184] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0030015C .text C:\WINDOWS\System32\svchost.exe[1184] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00300198 .text C:\WINDOWS\System32\svchost.exe[1184] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00300030 .text C:\WINDOWS\System32\svchost.exe[1184] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0030006C .text C:\WINDOWS\System32\svchost.exe[1184] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003000A8 .text C:\WINDOWS\System32\svchost.exe[1184] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003100E4 .text C:\WINDOWS\System32\svchost.exe[1184] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310120 .text C:\WINDOWS\System32\svchost.exe[1184] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003100A8 .text C:\WINDOWS\System32\svchost.exe[1184] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00310030 .text C:\WINDOWS\System32\svchost.exe[1184] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0031006C .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe[1200] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\WINDOWS\system32\hkcmd.exe[1248] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\WINDOWS\system32\hkcmd.exe[1248] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\WINDOWS\system32\hkcmd.exe[1248] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003F00E4 .text C:\WINDOWS\system32\hkcmd.exe[1248] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003F0120 .text C:\WINDOWS\system32\hkcmd.exe[1248] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003F00A8 .text C:\WINDOWS\system32\hkcmd.exe[1248] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003F0030 .text C:\WINDOWS\system32\hkcmd.exe[1248] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003F006C .text C:\WINDOWS\system32\hkcmd.exe[1248] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 004301D4 .text C:\WINDOWS\system32\hkcmd.exe[1248] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 004300E4 .text C:\WINDOWS\system32\hkcmd.exe[1248] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00430120 .text C:\WINDOWS\system32\hkcmd.exe[1248] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0043015C .text C:\WINDOWS\system32\hkcmd.exe[1248] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00430198 .text C:\WINDOWS\system32\hkcmd.exe[1248] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00430030 .text C:\WINDOWS\system32\hkcmd.exe[1248] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0043006C .text C:\WINDOWS\system32\hkcmd.exe[1248] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 004300A8 .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe[1260] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003F00E4 .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003F0120 .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003F00A8 .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003F0030 .text C:\Program Files\Java\jre6\bin\jqs.exe[1272] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003F006C .text C:\WINDOWS\system32\svchost.exe[1280] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\system32\svchost.exe[1280] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003001D4 .text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003000E4 .text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00300120 .text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0030015C .text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00300198 .text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00300030 .text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0030006C .text C:\WINDOWS\system32\svchost.exe[1280] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003000A8 .text C:\WINDOWS\system32\svchost.exe[1280] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003100E4 .text C:\WINDOWS\system32\svchost.exe[1280] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310120 .text C:\WINDOWS\system32\svchost.exe[1280] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003100A8 .text C:\WINDOWS\system32\svchost.exe[1280] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00310030 .text C:\WINDOWS\system32\svchost.exe[1280] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0031006C .text C:\WINDOWS\system32\svchost.exe[1316] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\system32\svchost.exe[1316] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\system32\svchost.exe[1316] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003001D4 .text C:\WINDOWS\system32\svchost.exe[1316] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003000E4 .text C:\WINDOWS\system32\svchost.exe[1316] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00300120 .text C:\WINDOWS\system32\svchost.exe[1316] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0030015C .text C:\WINDOWS\system32\svchost.exe[1316] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00300198 .text C:\WINDOWS\system32\svchost.exe[1316] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00300030 .text C:\WINDOWS\system32\svchost.exe[1316] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0030006C .text C:\WINDOWS\system32\svchost.exe[1316] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003000A8 .text C:\WINDOWS\system32\svchost.exe[1316] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003100E4 .text C:\WINDOWS\system32\svchost.exe[1316] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310120 .text C:\WINDOWS\system32\svchost.exe[1316] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003100A8 .text C:\WINDOWS\system32\svchost.exe[1316] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00310030 .text C:\WINDOWS\system32\svchost.exe[1316] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0031006C .text C:\Program Files\Messenger\msmsgs.exe[1352] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\Program Files\Messenger\msmsgs.exe[1352] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\Program Files\Messenger\msmsgs.exe[1352] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003201D4 .text C:\Program Files\Messenger\msmsgs.exe[1352] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003200E4 .text C:\Program Files\Messenger\msmsgs.exe[1352] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00320120 .text C:\Program Files\Messenger\msmsgs.exe[1352] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0032015C .text C:\Program Files\Messenger\msmsgs.exe[1352] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00320198 .text C:\Program Files\Messenger\msmsgs.exe[1352] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00320030 .text C:\Program Files\Messenger\msmsgs.exe[1352] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0032006C .text C:\Program Files\Messenger\msmsgs.exe[1352] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003200A8 .text C:\Program Files\Messenger\msmsgs.exe[1352] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003300E4 .text C:\Program Files\Messenger\msmsgs.exe[1352] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00330120 .text C:\Program Files\Messenger\msmsgs.exe[1352] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003300A8 .text C:\Program Files\Messenger\msmsgs.exe[1352] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00330030 .text C:\Program Files\Messenger\msmsgs.exe[1352] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0033006C .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003F00E4 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003F0120 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003F00A8 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003F0030 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe[1412] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003F006C .text C:\Program Files\Skype\Phone\Skype.exe[1416] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Skype\Phone\Skype.exe[1416] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Skype\Phone\Skype.exe[1416] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\Program Files\Skype\Phone\Skype.exe[1416] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\Program Files\Skype\Phone\Skype.exe[1416] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\Program Files\Skype\Phone\Skype.exe[1416] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\Program Files\Skype\Phone\Skype.exe[1416] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\Program Files\Skype\Phone\Skype.exe[1416] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\Program Files\Skype\Phone\Skype.exe[1416] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\Program Files\Skype\Phone\Skype.exe[1416] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\Program Files\Skype\Phone\Skype.exe[1416] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003F00E4 .text C:\Program Files\Skype\Phone\Skype.exe[1416] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003F0120 .text C:\Program Files\Skype\Phone\Skype.exe[1416] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003F00A8 .text C:\Program Files\Skype\Phone\Skype.exe[1416] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003F0030 .text C:\Program Files\Skype\Phone\Skype.exe[1416] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003F006C .text C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe[1444] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00140030 .text C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe[1444] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0014006C .text C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe[1444] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003D01D4 .text C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe[1444] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003D00E4 .text C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe[1444] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003D0120 .text C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe[1444] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003D015C .text C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe[1444] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003D0198 .text C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe[1444] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003D0030 .text C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe[1444] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003D006C .text C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe[1444] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003D00A8 .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe[1468] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe[1496] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 005300E4 .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00530120 .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 005300A8 .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00530030 .text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1508] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0053006C .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1568] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 4 Bytes [C2, 04, 00, 90] {RET 0x4; NOP } .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003F00E4 .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003F0120 .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003F00A8 .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003F0030 .text C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe[1632] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003F006C .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 01B201D4 .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 01B200E4 .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 01B20120 .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 01B2015C .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 01B20198 .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 01B20030 .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 01B2006C .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 01B200A8 .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 01B300E4 .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 01B30120 .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 01B300A8 .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 01B30030 .text C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe[1740] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 01B3006C .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe[1776] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\WINDOWS\Explorer.EXE[1808] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\Explorer.EXE[1808] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\Explorer.EXE[1808] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003101D4 .text C:\WINDOWS\Explorer.EXE[1808] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003100E4 .text C:\WINDOWS\Explorer.EXE[1808] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00310120 .text C:\WINDOWS\Explorer.EXE[1808] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0031015C .text C:\WINDOWS\Explorer.EXE[1808] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00310198 .text C:\WINDOWS\Explorer.EXE[1808] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00310030 .text C:\WINDOWS\Explorer.EXE[1808] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0031006C .text C:\WINDOWS\Explorer.EXE[1808] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003100A8 .text C:\WINDOWS\Explorer.EXE[1808] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003200E4 .text C:\WINDOWS\Explorer.EXE[1808] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00320120 .text C:\WINDOWS\Explorer.EXE[1808] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003200A8 .text C:\WINDOWS\Explorer.EXE[1808] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00320030 .text C:\WINDOWS\Explorer.EXE[1808] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0032006C .text C:\WINDOWS\system32\svchost.exe[1856] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 000A0030 .text C:\WINDOWS\system32\svchost.exe[1856] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 000A006C .text C:\WINDOWS\system32\svchost.exe[1856] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003101D4 .text C:\WINDOWS\system32\svchost.exe[1856] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003100E4 .text C:\WINDOWS\system32\svchost.exe[1856] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00310120 .text C:\WINDOWS\system32\svchost.exe[1856] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0031015C .text C:\WINDOWS\system32\svchost.exe[1856] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00310198 .text C:\WINDOWS\system32\svchost.exe[1856] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00310030 .text C:\WINDOWS\system32\svchost.exe[1856] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0031006C .text C:\WINDOWS\system32\svchost.exe[1856] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003100A8 .text C:\WINDOWS\system32\svchost.exe[1856] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003200E4 .text C:\WINDOWS\system32\svchost.exe[1856] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00320120 .text C:\WINDOWS\system32\svchost.exe[1856] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003200A8 .text C:\WINDOWS\system32\svchost.exe[1856] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00320030 .text C:\WINDOWS\system32\svchost.exe[1856] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0032006C .text C:\WINDOWS\system32\IoctlSvc.exe[2056] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\WINDOWS\system32\IoctlSvc.exe[2056] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\WINDOWS\system32\IoctlSvc.exe[2056] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\WINDOWS\system32\IoctlSvc.exe[2056] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\WINDOWS\system32\IoctlSvc.exe[2056] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\WINDOWS\system32\IoctlSvc.exe[2056] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\WINDOWS\system32\IoctlSvc.exe[2056] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\WINDOWS\system32\IoctlSvc.exe[2056] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\WINDOWS\system32\IoctlSvc.exe[2056] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\WINDOWS\system32\IoctlSvc.exe[2056] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\WINDOWS\system32\IoctlSvc.exe[2056] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003F00E4 .text C:\WINDOWS\system32\IoctlSvc.exe[2056] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003F0120 .text C:\WINDOWS\system32\IoctlSvc.exe[2056] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003F00A8 .text C:\WINDOWS\system32\IoctlSvc.exe[2056] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003F0030 .text C:\WINDOWS\system32\IoctlSvc.exe[2056] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003F006C .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00140030 .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0014006C .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003D01D4 .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003D00E4 .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003D0120 .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003D015C .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003D0198 .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003D0030 .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003D006C .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003D00A8 .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe[2096] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00140030 .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0014006C .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D00E4 .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003D0120 .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003D00A8 .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003D0030 .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003D006C .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe[2156] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\SRS Labs\SRS Premium Sound\SRS_VolSync.exe[2196] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\WINDOWS\system32\svchost.exe[2232] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\system32\svchost.exe[2232] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\system32\svchost.exe[2232] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003001D4 .text C:\WINDOWS\system32\svchost.exe[2232] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003000E4 .text C:\WINDOWS\system32\svchost.exe[2232] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00300120 .text C:\WINDOWS\system32\svchost.exe[2232] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0030015C .text C:\WINDOWS\system32\svchost.exe[2232] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00300198 .text C:\WINDOWS\system32\svchost.exe[2232] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00300030 .text C:\WINDOWS\system32\svchost.exe[2232] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0030006C .text C:\WINDOWS\system32\svchost.exe[2232] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003000A8 .text C:\WINDOWS\system32\svchost.exe[2232] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003100E4 .text C:\WINDOWS\system32\svchost.exe[2232] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310120 .text C:\WINDOWS\system32\svchost.exe[2232] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003100A8 .text C:\WINDOWS\system32\svchost.exe[2232] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00310030 .text C:\WINDOWS\system32\svchost.exe[2232] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0031006C .text C:\WINDOWS\system32\wdfmgr.exe[2260] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00080030 .text C:\WINDOWS\system32\wdfmgr.exe[2260] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0008006C .text C:\WINDOWS\system32\wdfmgr.exe[2260] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003101D4 .text C:\WINDOWS\system32\wdfmgr.exe[2260] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003100E4 .text C:\WINDOWS\system32\wdfmgr.exe[2260] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00310120 .text C:\WINDOWS\system32\wdfmgr.exe[2260] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0031015C .text C:\WINDOWS\system32\wdfmgr.exe[2260] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00310198 .text C:\WINDOWS\system32\wdfmgr.exe[2260] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00310030 .text C:\WINDOWS\system32\wdfmgr.exe[2260] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0031006C .text C:\WINDOWS\system32\wdfmgr.exe[2260] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003100A8 .text C:\WINDOWS\system32\wdfmgr.exe[2260] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003200E4 .text C:\WINDOWS\system32\wdfmgr.exe[2260] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00320120 .text C:\WINDOWS\system32\wdfmgr.exe[2260] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003200A8 .text C:\WINDOWS\system32\wdfmgr.exe[2260] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00320030 .text C:\WINDOWS\system32\wdfmgr.exe[2260] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0032006C .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003F00E4 .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003F0120 .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003F00A8 .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003F0030 .text C:\Program Files\Java\jre6\bin\jucheck.exe[2464] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003F006C .text C:\WINDOWS\system32\igfxpers.exe[2516] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\WINDOWS\system32\igfxpers.exe[2516] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\WINDOWS\system32\igfxpers.exe[2516] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\WINDOWS\system32\igfxpers.exe[2516] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\WINDOWS\system32\igfxpers.exe[2516] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\WINDOWS\system32\igfxpers.exe[2516] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\WINDOWS\system32\igfxpers.exe[2516] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\WINDOWS\system32\igfxpers.exe[2516] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\WINDOWS\system32\igfxpers.exe[2516] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\WINDOWS\system32\igfxpers.exe[2516] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\WINDOWS\system32\igfxpers.exe[2516] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\WINDOWS\system32\igfxpers.exe[2516] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\WINDOWS\system32\igfxpers.exe[2516] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\WINDOWS\system32\igfxpers.exe[2516] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\WINDOWS\system32\igfxpers.exe[2516] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\WINDOWS\System32\alg.exe[2572] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\System32\alg.exe[2572] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\System32\alg.exe[2572] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003000E4 .text C:\WINDOWS\System32\alg.exe[2572] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00300120 .text C:\WINDOWS\System32\alg.exe[2572] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003000A8 .text C:\WINDOWS\System32\alg.exe[2572] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00300030 .text C:\WINDOWS\System32\alg.exe[2572] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0030006C .text C:\WINDOWS\System32\alg.exe[2572] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003101D4 .text C:\WINDOWS\System32\alg.exe[2572] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003100E4 .text C:\WINDOWS\System32\alg.exe[2572] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00310120 .text C:\WINDOWS\System32\alg.exe[2572] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0031015C .text C:\WINDOWS\System32\alg.exe[2572] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00310198 .text C:\WINDOWS\System32\alg.exe[2572] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00310030 .text C:\WINDOWS\System32\alg.exe[2572] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0031006C .text C:\WINDOWS\System32\alg.exe[2572] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003100A8 .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003C01D4 .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003C00E4 .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003C0120 .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003C015C .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003C0198 .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003C0030 .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003C006C .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003C00A8 .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D00E4 .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003D0120 .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003D00A8 .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003D0030 .text C:\WINDOWS\system32\wbem\unsecapp.exe[2612] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003D006C .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003001D4 .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003000E4 .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00300120 .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0030015C .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00300198 .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00300030 .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0030006C .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003000A8 .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003100E4 .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310120 .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003100A8 .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00310030 .text C:\WINDOWS\system32\wbem\wmiapsrv.exe[2656] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0031006C .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003001D4 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003000E4 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00300120 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0030015C .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00300198 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00300030 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0030006C .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003000A8 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003100E4 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00310120 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003100A8 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00310030 .text C:\WINDOWS\system32\wbem\wmiprvse.exe[2680] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0031006C .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00140030 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0014006C .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D00E4 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003D0120 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003D00A8 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003D0030 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003D006C .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[2760] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\WINDOWS\system32\wscntfy.exe[2820] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00090030 .text C:\WINDOWS\system32\wscntfy.exe[2820] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0009006C .text C:\WINDOWS\system32\wscntfy.exe[2820] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003200E4 .text C:\WINDOWS\system32\wscntfy.exe[2820] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00320120 .text C:\WINDOWS\system32\wscntfy.exe[2820] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003200A8 .text C:\WINDOWS\system32\wscntfy.exe[2820] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00320030 .text C:\WINDOWS\system32\wscntfy.exe[2820] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0032006C .text C:\WINDOWS\system32\wscntfy.exe[2820] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003301D4 .text C:\WINDOWS\system32\wscntfy.exe[2820] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003300E4 .text C:\WINDOWS\system32\wscntfy.exe[2820] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00330120 .text C:\WINDOWS\system32\wscntfy.exe[2820] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 3 Bytes JMP 0033015C .text C:\WINDOWS\system32\wscntfy.exe[2820] ADVAPI32.dll!ChangeServiceConfig2A + 4 77E270DD 1 Byte [88] .text C:\WINDOWS\system32\wscntfy.exe[2820] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00330198 .text C:\WINDOWS\system32\wscntfy.exe[2820] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00330030 .text C:\WINDOWS\system32\wscntfy.exe[2820] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0033006C .text C:\WINDOWS\system32\wscntfy.exe[2820] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003300A8 .text C:\Documents and Settings\Jan\Moje dokumenty\Pobieranie\z7hvp34e.exe[3128] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Documents and Settings\Jan\Moje dokumenty\Pobieranie\z7hvp34e.exe[3128] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.exe[3200] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 007001D4 .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 007000E4 .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00700120 .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0070015C .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00700198 .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00700030 .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0070006C .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 007000A8 .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 007100E4 .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00710120 .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 007100A8 .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00710030 .text C:\Program Files\Mozilla Firefox\firefox.exe[3204] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0071006C .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00140030 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0014006C .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003D00E4 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003D0120 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003D00A8 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003D0030 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003D006C .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\Documents and Settings\Jan\Ustawienia lokalne\Dane aplikacji\Akamai\netsession_win.exe[3228] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3256] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe[3328] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003F00E4 .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003F0120 .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003F00A8 .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003F0030 .text C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe[3392] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003F006C .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00050030 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0005006C .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 002E00E4 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 002E0120 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 002E00A8 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 002E0030 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 002E006C .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 002F01D4 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 002F00E4 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 002F0120 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 002F015C .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 002F0198 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 002F0030 .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 002F006C .text C:\Program Files\OpenOffice.ux.pl 3\program\soffice.bin[3652] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 002F00A8 .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00140030 .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0014006C .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003D01D4 .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003D00E4 .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003D0120 .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003D015C .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003D0198 .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003D0030 .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003D006C .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003D00A8 .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe[3784] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\ASUS\ATK Hotkey\MsgTranAgt.exe[3816] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\ASUS\ATK Hotkey\HControlUser.exe[3824] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\ASUS\ATK Hotkey\HControl.exe[3836] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\ASUS\ATK Media\DMedia.exe[3872] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe[3904] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe[3904] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe[3904] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe[3904] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe[3904] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe[3904] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\ASUS\ATK Hotkey\ATKOSD.exe[3904] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\ASUS\ATKOSD2\ATKOSD2.exe[3912] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe[3928] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003E01D4 .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003E00E4 .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003E0120 .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003E015C .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003E0198 .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003E0030 .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003E006C .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003E00A8 .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003F00E4 .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003F0120 .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003F00A8 .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003F0030 .text C:\Program Files\ASUS\ASUS Live Update\ALU.exe[3960] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003F006C .text C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe[3976] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe[3976] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe[3976] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe[3976] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe[3976] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe[3976] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\ASUS\ATK Hotkey\KBFiltr.exe[3976] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 005300E4 .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 00530120 .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 005300A8 .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 00530030 .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 0053006C .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 005401D4 .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 005400E4 .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 00540120 .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 0054015C .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 00540198 .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 00540030 .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 0054006C .text C:\Program Files\ASUS\Net4Switch\Net4Switch.exe[3984] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 005400A8 .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003F01D4 .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003F00E4 .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003F0120 .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003F015C .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003F0198 .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003F0030 .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003F006C .text C:\Program Files\ASUS\ATK Hotkey\WDC.exe[4012] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003F00A8 .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00150030 .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0015006C .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 005C01D4 .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 005C00E4 .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 005C0120 .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 005C015C .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 005C0198 .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 005C0030 .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 005C006C .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 005C00A8 .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 005D00E4 .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 005D0120 .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 005D00A8 .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 005D0030 .text C:\Program Files\ASUS\Wireless Console 3\wcourier.exe[4020] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 005D006C .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00140030 .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0014006C .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003D01D4 .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003D00E4 .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003D0120 .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003D015C .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003D0198 .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003D0030 .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003D006C .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003D00A8 .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe[4028] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C .text C:\WINDOWS\AsScrPro.exe[4060] ntdll.dll!LdrLoadDll 7C9163A3 5 Bytes JMP 00140030 .text C:\WINDOWS\AsScrPro.exe[4060] ntdll.dll!LdrUnloadDll 7C91736B 5 Bytes JMP 0014006C .text C:\WINDOWS\AsScrPro.exe[4060] ADVAPI32.dll!SetServiceObjectSecurity 77E26D59 5 Bytes JMP 003D01D4 .text C:\WINDOWS\AsScrPro.exe[4060] ADVAPI32.dll!ChangeServiceConfigA 77E26E41 5 Bytes JMP 003D00E4 .text C:\WINDOWS\AsScrPro.exe[4060] ADVAPI32.dll!ChangeServiceConfigW 77E26FD9 5 Bytes JMP 003D0120 .text C:\WINDOWS\AsScrPro.exe[4060] ADVAPI32.dll!ChangeServiceConfig2A 77E270D9 5 Bytes JMP 003D015C .text C:\WINDOWS\AsScrPro.exe[4060] ADVAPI32.dll!ChangeServiceConfig2W 77E27161 5 Bytes JMP 003D0198 .text C:\WINDOWS\AsScrPro.exe[4060] ADVAPI32.dll!CreateServiceA 77E271E9 5 Bytes JMP 003D0030 .text C:\WINDOWS\AsScrPro.exe[4060] ADVAPI32.dll!CreateServiceW 77E27381 5 Bytes JMP 003D006C .text C:\WINDOWS\AsScrPro.exe[4060] ADVAPI32.dll!DeleteService 77E27489 5 Bytes JMP 003D00A8 .text C:\WINDOWS\AsScrPro.exe[4060] USER32.dll!SetWindowsHookExW 7E37820F 5 Bytes JMP 003E00E4 .text C:\WINDOWS\AsScrPro.exe[4060] USER32.dll!UnhookWindowsHookEx 7E37D5F3 5 Bytes JMP 003E0120 .text C:\WINDOWS\AsScrPro.exe[4060] USER32.dll!SetWindowsHookExA 7E381211 5 Bytes JMP 003E00A8 .text C:\WINDOWS\AsScrPro.exe[4060] USER32.dll!SetWinEventHook 7E3817F7 5 Bytes JMP 003E0030 .text C:\WINDOWS\AsScrPro.exe[4060] USER32.dll!UnhookWinEvent 7E3818AC 5 Bytes JMP 003E006C ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\WINDOWS\system32\services.exe[912] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00630002 IAT C:\WINDOWS\system32\services.exe[912] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00630000 ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software) AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software) AttachedDevice \FileSystem\Ntfs \Ntfs AsDsm.sys (Data Security Manager Driver/ASUSTek Computer Inc) AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x04 0x30 0x88 0xDE ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\ Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x43 0xB8 0x7E 0x12 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x40 0x47 0x74 0xEF ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xBB 0x3E 0xBD 0x52 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x04 0x30 0x88 0xDE ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x43 0xB8 0x7E 0x12 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0x40 0x47 0x74 0xEF ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0xBB 0x3E 0xBD 0x52 ... ---- Files - GMER 1.0.15 ---- File C:\ADSM_PData_0150\DB 0 bytes File C:\ADSM_PData_0150\DB\SI.db 624 bytes File C:\ADSM_PData_0150\DB\UL.db 16 bytes File C:\ADSM_PData_0150\DB\VL.db 16 bytes File C:\ADSM_PData_0150\DB\WAL.db 2048 bytes File C:\ADSM_PData_0150\DragWait.exe 315392 bytes executable File C:\ADSM_PData_0150\_avt 512 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\A0169347.old 100196 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\A0169353.lnk 1020 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\A0169354.lnk 817 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\A0169355.lnk 817 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\A0169356.lnk 421 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\A0169363.ini 224 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\A0169364.ilg 195584 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\A0169365.exe 166912 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\A0169366.lnk 645 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\change.log.1 114766 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\drivetable.txt 268 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\RestorePointSize 8 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\rp.log 536 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\ComDb.Dat 22808 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\domain.txt 50 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\Repository 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\Repository\$WinMgmt.CFG 20 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\Repository\FS 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\Repository\FS\INDEX.BTR 1605632 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\Repository\FS\INDEX.MAP 844 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\Repository\FS\MAPPING.VER 4 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\Repository\FS\MAPPING1.MAP 13128 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\Repository\FS\MAPPING2.MAP 13128 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\Repository\FS\OBJECTS.DATA 25059328 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\Repository\FS\OBJECTS.MAP 12292 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\_REGISTRY_MACHINE_SAM 24576 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\_REGISTRY_MACHINE_SECURITY 81920 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\_REGISTRY_MACHINE_SOFTWARE 47202304 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\_REGISTRY_MACHINE_SYSTEM 4636672 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\_REGISTRY_USER_.DEFAULT 274432 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18 262144 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19 245760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20 245760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-1123561945-1078145449-1606980848-1003 9433088 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19 8192 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20 8192 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP422\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-1123561945-1078145449-1606980848-1003 421888 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\A0169370.old 88028 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\A0169371.ini 2672 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\A0169372.ini 1710 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\A0169373.old 3330 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\A0169374.ini 36690 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\change.log.1 60242 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\drivetable.txt 268 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\RestorePointSize 8 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\rp.log 536 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\ComDb.Dat 22808 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\domain.txt 50 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\Repository 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\Repository\$WinMgmt.CFG 20 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\Repository\FS 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\Repository\FS\INDEX.BTR 1605632 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\Repository\FS\INDEX.MAP 844 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\Repository\FS\MAPPING.VER 4 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\Repository\FS\MAPPING1.MAP 13128 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\Repository\FS\MAPPING2.MAP 13128 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\Repository\FS\OBJECTS.DATA 25059328 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\Repository\FS\OBJECTS.MAP 12292 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\_REGISTRY_MACHINE_SAM 24576 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\_REGISTRY_MACHINE_SECURITY 81920 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\_REGISTRY_MACHINE_SOFTWARE 47202304 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\_REGISTRY_MACHINE_SYSTEM 4636672 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\_REGISTRY_USER_.DEFAULT 274432 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18 262144 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19 245760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20 245760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-1123561945-1078145449-1606980848-1003 9433088 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19 8192 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20 8192 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP423\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-1123561945-1078145449-1606980848-1003 421888 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169392.ini 300 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169410.dll 178176 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169375.dll 2676224 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169376.ini 300 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169377.dll 2846720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169378.ini 300 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169379.dll 563712 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169380.ini 300 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169381.dll 567296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169382.ini 300 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169383.dll 576000 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169384.ini 300 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169385.dll 577024 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169386.ini 300 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169387.dll 577536 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169388.ini 300 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169389.dll 577536 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169390.ini 300 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169391.dll 578560 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169393.dll 223232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169394.ini 280 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169395.dll 53248 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169396.ini 318 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169397.dll 12800 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169398.ini 304 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169399.dll 473600 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169400.ini 298 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169401.dll 578560 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169402.ini 300 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169403.dll 145920 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169404.ini 302 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169405.dll 159232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169406.ini 304 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169407.old 87761 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169408.dll 364544 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169409.ini 302 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169411.ini 304 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169412.dll 3850760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169413.dll 467984 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169414.dll 1491992 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169415.dll 25608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169416.dll 238088 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169417.dll 507400 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169418.dll 65032 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169419.dll 23376 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169420.dll 235856 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169421.dll 514384 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169422.dll 70992 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169423.dll 4379984 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169424.dll 452440 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\A0169425.dll 2036576 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\change.log.1 224930 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\drivetable.txt 268 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\RestorePointSize 8 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\rp.log 536 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\ComDb.Dat 22808 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\domain.txt 50 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\Repository 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\Repository\$WinMgmt.CFG 20 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\Repository\FS 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\Repository\FS\INDEX.BTR 1605632 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\Repository\FS\INDEX.MAP 844 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\Repository\FS\MAPPING.VER 4 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\Repository\FS\MAPPING1.MAP 13128 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\Repository\FS\MAPPING2.MAP 13128 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\Repository\FS\OBJECTS.DATA 25059328 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\Repository\FS\OBJECTS.MAP 12292 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\_REGISTRY_MACHINE_SAM 24576 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\_REGISTRY_MACHINE_SECURITY 81920 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\_REGISTRY_MACHINE_SOFTWARE 47202304 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\_REGISTRY_MACHINE_SYSTEM 4636672 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\_REGISTRY_USER_.DEFAULT 274432 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18 262144 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19 245760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20 245760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-1123561945-1078145449-1606980848-1003 9433088 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19 8192 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20 8192 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP424\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-1123561945-1078145449-1606980848-1003 421888 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169443.rbf 333088 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169461.rbf 316704 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169426.old 87689 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169427.rbf 390424 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169428.rbf 4146456 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169429.rbf 385792 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169430.rbf 2724608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169431.rbf 390424 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169432.rbf 3990808 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169433.rbf 386336 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169434.rbf 2659616 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169435.rbf 410912 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169436.rbf 2946336 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169437.rbf 337184 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169438.rbf 2503968 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169439.rbf 337184 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169440.rbf 2475296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169441.rbf 333088 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169442.rbf 2397472 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169444.rbf 2393376 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169445.rbf 337184 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169446.rbf 2340128 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169447.rbf 337184 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169448.rbf 2311456 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169449.rbf 337184 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169450.rbf 2311456 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169451.rbf 337184 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169452.rbf 2311456 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169453.rbf 333088 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169454.rbf 2295072 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169455.rbf 341280 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169456.rbf 1877280 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169457.rbf 341280 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169458.rbf 1869088 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169459.rbf 341280 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169460.rbf 1869088 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169462.rbf 1377568 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169463.rbf 316704 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169464.rbf 1377568 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169465.rbf 230688 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169466.rbf 1303840 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169467.rbf 70936 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169468.rbf 23320 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169469.rbf 390424 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169470.rbf 4146456 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169471.rbf 398616 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169472.rbf 4154648 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169473.rbf 390424 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169474.rbf 4416792 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169475.rbf 390424 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169476.rbf 4097304 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169477.rbf 390424 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169478.rbf 4384024 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169479.rbf 1607 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169480.MSI 34012672 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169481.dll 200704 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169482.ini 61667 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169483.msi 34132480 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169484.mst 41984 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169485.msi 1454592 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\A0169486.ico 25214 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\change.log.1 147238 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\drivetable.txt 268 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\RestorePointSize 8 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\rp.log 536 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\ComDb.Dat 22808 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\domain.txt 50 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\Repository 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\Repository\$WinMgmt.CFG 20 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\Repository\FS 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\Repository\FS\INDEX.BTR 1605632 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\Repository\FS\INDEX.MAP 844 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\Repository\FS\MAPPING.VER 4 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\Repository\FS\MAPPING1.MAP 13128 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\Repository\FS\MAPPING2.MAP 13128 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\Repository\FS\OBJECTS.DATA 25059328 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\Repository\FS\OBJECTS.MAP 12292 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\_REGISTRY_MACHINE_SAM 24576 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\_REGISTRY_MACHINE_SECURITY 81920 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\_REGISTRY_MACHINE_SOFTWARE 47202304 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\_REGISTRY_MACHINE_SYSTEM 4636672 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\_REGISTRY_USER_.DEFAULT 274432 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18 262144 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19 245760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20 245760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-1123561945-1078145449-1606980848-1003 9433088 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19 8192 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20 8192 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP425\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-1123561945-1078145449-1606980848-1003 421888 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169487.old 86159 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169488.msi 23406080 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169489.exe 2959376 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169490.exe 242743296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169491.msi 23406080 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169492.msi 5732864 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169493.exe 1417216 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169494.ini 8070 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169496.INI 46346 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169497.INI 101 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169498.old 3330 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169499.old 99 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169500.old 4196 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169501.ini 188 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169502.ini 62 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169503.ini 62 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169504.ini 62 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169506.dll 1123696 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169507.dll 1124720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169508.dll 1358192 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169509.dll 1374232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169510.dll 1420824 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169511.dll 1491992 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169512.dll 1493528 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169513.dll 2036576 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169514.dll 443752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169515.dll 443752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169516.dll 444776 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169517.dll 444776 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169518.dll 462864 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169519.dll 467984 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169520.dll 467984 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169521.dll 452440 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169522.dll 2222800 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169524.dll 2297552 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169525.dll 2319568 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169526.dll 2323664 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169527.dll 2332368 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169528.dll 2388176 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169529.dll 2414360 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169530.dll 3426072 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169531.dll 3495784 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169532.dll 3497832 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169533.dll 3727720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169534.dll 3734536 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169535.dll 3786760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169536.dll 3850760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169537.dll 3851784 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169538.dll 4379984 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169539.dll 14032 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169540.dll 15128 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169542.dll 25608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169543.dll 25608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169544.dll 23376 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169545.dll 230096 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169546.dll 229584 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169547.dll 267272 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169548.dll 230168 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169549.dll 236824 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169550.dll 237848 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169551.dll 251672 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169552.dll 255848 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169553.dll 261480 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169554.dll 266088 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169555.dll 267112 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169556.dll 238088 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169557.dll 238088 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169558.dll 238088 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169560.dll 65032 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169561.dll 68616 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169562.dll 70992 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169563.dll 479752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169564.dll 507400 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169565.dll 509448 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169566.dll 514384 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169567.dll 62672 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169568.dll 62744 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169569.dll 81768 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169570.dll 61136 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169571.inf 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169572.PNF 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169573.ini 2672 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169574.ini 1044 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169575.vpx 598 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169576.ini 89344 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169578.vpx 851 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169579.vpx 824690 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169580.vpx 59357934 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169581.vpx 6352055 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169582.ini 89344 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169583.INI 46346 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169584.ini 222 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169585.icm 2076 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169586.ini 32 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169587.ini 89344 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169588.ini 1710 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169589.mfl 30470 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169590.dll 1691136 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169591.dll 47352 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169592.dll 173488 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169593.dll 1630456 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169594.dll 450136 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169505.ini 10090 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169523.dll 2337488 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169541.dll 17928 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169559.dll 235856 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169577.vpx 2079 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169595.dll 342968 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169613.dll 58368 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169631.dll 95232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169649.dll 130048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169667.exe 3140608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169685.dll 58368 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169701.dll 4126720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169719.exe 163328 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169737.exe 3140608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169755.dll 51712 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169773.dll 95232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169791.dll 3486048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169808.dll 121344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169826.dll 130048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169844.ini 89344 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169916.ini 62 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170919.ini 2672 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169596.dll 184312 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169597.dll 100400 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169598.dll 1233888 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169599.dll 394968 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169600.dll 360448 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169601.dll 269832 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169602.dll 100400 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169603.ini 10412 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169604.dll 13872 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169605.dll 40672 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169606.dll 44744 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169607.mfl 1947911 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169608.properties 596 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169609.ini 36690 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169610.sys 2016704 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169611.dll 58368 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169612.dll 58368 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169614.dll 58368 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169615.dll 58368 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169616.dll 183296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169617.dll 183296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169618.dll 183296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169619.dll 183296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169620.dll 183296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169621.dll 3486048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169622.dll 3486048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169623.dll 3486048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169624.dll 3486048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169625.dll 3486048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169626.dll 4126720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169627.dll 4126720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169628.dll 4126720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169629.dll 4126720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169630.dll 4126720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169632.dll 95232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169633.dll 95232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169634.dll 95232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169635.dll 95232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169636.dll 57344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169637.dll 57344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169638.dll 57344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169639.dll 57344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169640.dll 57344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169641.exe 257536 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169642.dll 194048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169643.cpl 115200 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169644.dll 214016 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169645.dll 214016 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169646.dll 214016 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169647.dll 214016 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169648.dll 214016 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169650.exe 129536 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169651.exe 163328 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169652.exe 163328 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169653.exe 163328 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169654.exe 163328 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169655.exe 163328 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169656.dll 828928 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169657.exe 138752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169658.exe 138752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169659.exe 138752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169660.exe 138752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169661.exe 138752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169662.dll 121344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169663.dll 121344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169664.dll 121344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169665.dll 121344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169666.dll 121344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169668.exe 3140608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169669.exe 3140608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169670.exe 3140608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169671.exe 3140608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169672.config 151 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169673.dll 4096 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169674.dll 4096 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169675.dll 4096 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169676.dll 4096 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169677.dll 4096 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169678.exe 172032 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169679.dll 23552 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169680.dll 11345920 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169681.cat 30686 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169682.PNF 88844 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169683.dll 58368 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169684.dll 58368 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169686.dll 58368 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169687.dll 58368 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169688.dll 183296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169689.dll 183296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169690.dll 183296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169691.dll 183296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169692.dll 183296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169693.dll 3486048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169694.dll 3486048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169695.dll 3486048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169696.dll 3486048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169697.dll 3486048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169698.dll 4126720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169699.dll 4126720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169700.dll 4126720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169702.dll 4126720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169703.dll 95232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169704.dll 95232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169705.dll 95232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169706.dll 95232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169707.dll 95232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169708.dll 57344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169709.dll 57344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169710.dll 57344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169711.dll 57344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169712.dll 57344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169713.dll 214016 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169714.dll 214016 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169715.dll 214016 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169716.dll 214016 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169717.dll 214016 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169718.exe 163328 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169720.exe 163328 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169721.exe 163328 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169722.exe 163328 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169723.exe 138752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169724.exe 138752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169725.exe 138752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169726.exe 138752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169727.exe 138752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169728.dll 121344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169729.dll 121344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169730.dll 121344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169731.dll 121344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169732.dll 121344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169733.exe 3140608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169734.exe 3140608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169735.exe 3140608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169736.exe 3140608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169738.dll 4096 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169739.dll 4096 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169740.dll 4096 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169741.dll 4096 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169742.dll 4096 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169743.dll 94720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169744.exe 173592 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169745.dll 11345920 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169746.cpl 115200 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169747.dll 206848 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169748.dll 130048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169749.dll 23552 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169750.exe 172032 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169751.cat 30686 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169752.exe 142360 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169753.dll 199168 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169754.dll 5702656 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169756.exe 250904 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169757.exe 129536 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169758.PNF 88844 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169759.dll 2900256 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169760.dll 3439616 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169761.dll 212480 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169762.sys 2016704 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169763.dll 57344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169764.PNF 18450 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169765.PNF 7848 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169766.PNF 9520 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169767.PNF 101868 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169768.CAT 45037 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169769.inf 79545 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169770.dll 121344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169771.exe 3140608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169772.config 151 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169774.exe 163328 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169775.dll 11345920 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169776.cpl 115200 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169777.dll 214016 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169778.dll 4096 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169779.dll 130048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169780.dll 23552 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169781.exe 172032 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169782.cat 45037 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169783.exe 138752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169784.dll 194048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169785.dll 828928 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169786.dll 57344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169787.exe 257536 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169788.exe 129536 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169789.inf 79545 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169790.dll 81920 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169792.dll 4126720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169793.dll 183296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169794.sys 2016704 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169795.dll 58368 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169796.exe 953112 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169797.INI 101 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169798.ini 188 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169799.dll 58368 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169800.dll 183296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169801.dll 3486048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169802.dll 4126720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169803.dll 95232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169804.dll 57344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169805.dll 214016 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169806.exe 163328 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169807.exe 138752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169809.exe 3140608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169810.dll 4096 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169811.ini 62 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169812.ini 62 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169813.ini 62 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169814.ini 10090 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169815.sys 2016704 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169816.dll 121344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169817.exe 3140608 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169818.config 151 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169819.dll 95232 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169820.exe 163328 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169821.dll 11345920 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169822.dll 81920 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169823.cpl 115200 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169824.dll 214016 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169825.dll 4096 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169827.dll 23552 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169828.exe 172032 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169829.exe 138752 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169830.dll 194048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169831.dll 828928 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169832.dll 57344 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169833.exe 257536 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169834.exe 129536 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169835.dll 3486048 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169836.dll 4126720 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169837.dll 183296 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169838.dll 58368 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169839.inf 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169840.PNF 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169841.ini 2672 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169842.ini 1044 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169843.ini 89344 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169845.INI 46346 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169846.ini 222 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169847.icm 2076 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169848.ini 1710 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169852.mfl 2192238 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169853.mfl 1947911 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169854.ini 36690 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169886.lnk 661 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169887.lnk 597 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169888.lnk 597 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169889.lnk 589 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169890.lnk 594 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169912.sys 685816 bytes executable File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169913.INI 101 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169914.ini 188 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169915.ini 62 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169917.ini 62 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169918.ini 10090 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169919.ini 2672 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169920.ini 1033 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169921.ini 89344 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169922.ini 89344 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169923.ini 222 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169924.icm 2076 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169925.INI 46346 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169926.ini 1710 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169927.mfl 1947911 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169928.mfl 2198014 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0169929.ini 36690 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170915.ini 62 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170916.ini 62 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170917.ini 62 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170918.ini 8110 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170920.ini 1044 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170921.ini 89344 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170922.ini 89344 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170923.INI 46346 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170924.ini 222 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170925.icm 2076 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170926.ini 1710 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170927.mfl 196604 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170928.mfl 1947911 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170929.ini 36690 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\A0170930.lnk 745 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\change.log 29980 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\change.log.1 95796 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\change.log.2 211736 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\change.log.3 60302 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\change.log.4 20892 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\RestorePointSize 8 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\rp.log 536 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\ComDb.Dat 22808 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\domain.txt 50 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\Repository 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\Repository\$WinMgmt.CFG 20 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\Repository\FS 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\Repository\FS\INDEX.BTR 1605632 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\Repository\FS\INDEX.MAP 844 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\Repository\FS\MAPPING.VER 4 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\Repository\FS\MAPPING1.MAP 13128 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\Repository\FS\MAPPING2.MAP 13128 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\Repository\FS\OBJECTS.DATA 25059328 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\Repository\FS\OBJECTS.MAP 12292 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\_REGISTRY_MACHINE_SAM 24576 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\_REGISTRY_MACHINE_SECURITY 81920 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\_REGISTRY_MACHINE_SOFTWARE 47325184 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\_REGISTRY_MACHINE_SYSTEM 4640768 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\_REGISTRY_USER_.DEFAULT 274432 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18 262144 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19 245760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20 245760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-1123561945-1078145449-1606980848-1003 9433088 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19 8192 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20 8192 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP426\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-1123561945-1078145449-1606980848-1003 421888 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\A0159213.lnk 460 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\change.log.1 2108 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\drivetable.txt 268 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\RestorePointSize 8 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\rp.log 536 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\ComDb.Dat 22808 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\domain.txt 50 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\Repository 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\Repository\$WinMgmt.CFG 20 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\Repository\FS 0 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\Repository\FS\INDEX.BTR 1605632 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\Repository\FS\INDEX.MAP 844 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\Repository\FS\MAPPING.VER 4 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\Repository\FS\MAPPING1.MAP 13128 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\Repository\FS\MAPPING2.MAP 13128 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\Repository\FS\OBJECTS.DATA 25059328 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\Repository\FS\OBJECTS.MAP 12292 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\_REGISTRY_MACHINE_SAM 24576 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\_REGISTRY_MACHINE_SECURITY 81920 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\_REGISTRY_MACHINE_SOFTWARE 41836544 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\_REGISTRY_MACHINE_SYSTEM 4534272 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\_REGISTRY_USER_.DEFAULT 274432 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18 262144 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19 245760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20 245760 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-1123561945-1078145449-1606980848-1003 8777728 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19 8192 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20 8192 bytes File C:\System Volume Information\_restore{073A0C22-E2EB-45F4-88BE-7FC2140A02FC}\RP389\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-1123561945-1078145449-1606980848-1003 421888 bytes File C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$ 0 bytes File C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst 0 bytes File C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe 213216 bytes executable File C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.inf 4149 bytes File C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.txt 204 bytes File C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\updspapi.dll 371424 bytes executable File C:\WINDOWS\$NtUninstallKB942288-v3$ 0 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\msi.dll 2843136 bytes executable File C:\WINDOWS\$NtUninstallKB942288-v3$\msiexec.exe 78848 bytes executable File C:\WINDOWS\$NtUninstallKB942288-v3$\msihnd.dll 271360 bytes executable File C:\WINDOWS\$NtUninstallKB942288-v3$\msimsg.dll 884736 bytes executable File C:\WINDOWS\$NtUninstallKB942288-v3$\msisip.dll 15360 bytes executable File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00013 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00014 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00015 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00016 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00017 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00018 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00019 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00020 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00021 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00022 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00023 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00024 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00025 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00026 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00028 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00029 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00030 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00031 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00032 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00033 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00034 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00035 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00036 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00037 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00039 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00040 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00041 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00042 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00043 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00044 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00045 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00046 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00047 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00049 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00052 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00053 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00054 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00055 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00056 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00057 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00058 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00059 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00060 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00061 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00062 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00063 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00064 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00065 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00066 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00067 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00068 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00069 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00071 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00072 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00073 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00074 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00075 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00076 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00077 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00078 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00079 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00080 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00081 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00082 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00083 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00084 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00085 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00086 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00087 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00088 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00089 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00091 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00092 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00093 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00094 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00095 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00096 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00097 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00098 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00099 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00100 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00101 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00102 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00103 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00104 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00105 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00106 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00107 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00108 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00109 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00110 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00111 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00112 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00113 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00114 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00115 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00116 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00117 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\spuninst 0 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\spuninst\spuninst.exe 234360 bytes executable File C:\WINDOWS\$NtUninstallKB942288-v3$\spuninst\spuninst.inf 26036 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\spuninst\spuninst.txt 3041 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\spuninst\updspapi.dll 398200 bytes executable File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00027 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00048 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00070 8192 bytes File C:\WINDOWS\$NtUninstallKB942288-v3$\reg00090 8192 bytes File C:\WINDOWS\$NtUninstallKB952011$ 0 bytes File C:\WINDOWS\$NtUninstallKB952011$\spuninst 0 bytes File C:\WINDOWS\$NtUninstallKB952011$\spuninst\spuninst.exe 221488 bytes executable File C:\WINDOWS\$NtUninstallKB952011$\spuninst\spuninst.inf 11959 bytes File C:\WINDOWS\$NtUninstallKB952011$\spuninst\spuninst.txt 347 bytes File C:\WINDOWS\$NtUninstallKB952011$\spuninst\updspapi.dll 379184 bytes executable File C:\WINDOWS\$NtUninstallXPSEPSCLP$ 0 bytes File C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst 0 bytes File C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe 0 bytes File C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.inf 0 bytes File C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.txt 0 bytes File C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\updspapi.dll 0 bytes File C:\WINDOWS\0.log 0 bytes File C:\WINDOWS\addins 0 bytes File C:\WINDOWS\AppPatch 0 bytes File C:\WINDOWS\ARJ.PIF 0 bytes File C:\WINDOWS\AsCDProc.log 0 bytes File C:\WINDOWS\AsCD_Item_1.jpg 0 bytes File C:\WINDOWS\AsCD_Item_2.jpg 0 bytes File C:\WINDOWS\AsCD_Item_3.jpg 0 bytes File C:\WINDOWS\AsCD_Item_4.jpg 0 bytes File C:\WINDOWS\AsCD_Item_5.jpg 0 bytes File C:\WINDOWS\AsCD_Item_6.jpg 0 bytes File C:\WINDOWS\AsCD_Item_7.jpg 0 bytes File C:\WINDOWS\AsCD_Item_8.jpg 0 bytes ---- EOF - GMER 1.0.15 ----