GMER 1.0.12.12011 -
http://www.gmer.netRootkit scan 2007-01-15 11:07:41
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.12 ----
SSDT sptd.sys ZwCreateKey
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT sptd.sys ZwOpenKey
SSDT \??\C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT sptd.sys ZwSetValueKey
SSDT \??\C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
Code 82BDCCBE IoWriteTransferCount
---- Kernel code sections - GMER 1.0.12 ----
.text USBPORT.SYS!DllUnload F6B0962C 5 Bytes JMP 87075780
---- User code sections - GMER 1.0.12 ----
.text C:\Programmer\Easy CD & DVD Cover Creator\Easy CD Cover Creator.exe[168] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\Easy CD & DVD Cover Creator\Easy CD Cover Creator.exe[168] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\Easy CD & DVD Cover Creator\Easy CD Cover Creator.exe[168] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\Easy CD & DVD Cover Creator\Easy CD Cover Creator.exe[168] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Programmer\Easy CD & DVD Cover Creator\Easy CD Cover Creator.exe[168] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\Easy CD & DVD Cover Creator\Easy CD Cover Creator.exe[168] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\Easy CD & DVD Cover Creator\Easy CD Cover Creator.exe[168] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\ESET\nod32krn.exe[256] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\ESET\nod32krn.exe[256] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\ESET\nod32krn.exe[256] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\ESET\nod32krn.exe[256] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\ESET\nod32krn.exe[256] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\ESET\nod32krn.exe[256] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[272] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[272] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\svchost.exe[272] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[272] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[272] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[272] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[280] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[280] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[280] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[280] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[280] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\nvsvc32.exe[280] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\SPYWAR~1\swdoctor.exe[332] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRA~1\SPYWAR~1\swdoctor.exe[332] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\PROGRA~1\SPYWAR~1\swdoctor.exe[332] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\PROGRA~1\SPYWAR~1\swdoctor.exe[332] user32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\PROGRA~1\SPYWAR~1\swdoctor.exe[332] user32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRA~1\SPYWAR~1\swdoctor.exe[332] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\Spyware Doctor\sdhelp.exe[364] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\Spyware Doctor\sdhelp.exe[364] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\Spyware Doctor\sdhelp.exe[364] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\Spyware Doctor\sdhelp.exe[364] user32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\Spyware Doctor\sdhelp.exe[364] user32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\Spyware Doctor\sdhelp.exe[364] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\gmer.exe[540] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\gmer.exe[540] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\gmer.exe[540] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\gmer.exe[540] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Documents and Settings\Ejer\Skrivebord\gmer.exe[540] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\gmer.exe[540] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\gmer.exe[540] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[664] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[664] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[664] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[664] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[664] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\wdfmgr.exe[664] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\csrss.exe[720] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\csrss.exe[720] KERNEL32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\csrss.exe[720] KERNEL32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\csrss.exe[720] KERNEL32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\csrss.exe[720] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\csrss.exe[720] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[752] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[752] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[752] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[752] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[752] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[752] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\services.exe[796] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\services.exe[796] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\services.exe[796] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\services.exe[796] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\services.exe[796] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\services.exe[796] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[956] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[956] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\svchost.exe[956] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[956] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[956] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[956] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1016] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1016] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1016] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1016] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1016] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1016] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1092] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1092] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1092] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1092] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\MsPMSPSv.exe[1120] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\MsPMSPSv.exe[1120] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\MsPMSPSv.exe[1120] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\MsPMSPSv.exe[1120] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\MsPMSPSv.exe[1120] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\MsPMSPSv.exe[1120] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1168] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1168] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1168] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1168] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1168] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1168] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1288] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1288] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1288] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1288] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1288] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\svchost.exe[1288] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1444] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1444] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1444] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1444] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1444] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1444] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1696] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1696] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1696] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1696] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1696] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\Grisoft\AVG Anti-Spyware 7.5\guard.exe[1696] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\explorer.exe[1812] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\explorer.exe[1812] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\explorer.exe[1812] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\explorer.exe[1812] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\explorer.exe[1812] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\explorer.exe[1812] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\QuickTime\qttask.exe[1828] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\QuickTime\qttask.exe[1828] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\QuickTime\qttask.exe[1828] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\QuickTime\qttask.exe[1828] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\QuickTime\qttask.exe[1828] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\QuickTime\qttask.exe[1828] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe[1872] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe[1872] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe[1872] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe[1872] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe[1872] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe[1872] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\DAEMON Tools\daemon.exe[1924] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\DAEMON Tools\daemon.exe[1924] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\DAEMON Tools\daemon.exe[1924] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\DAEMON Tools\daemon.exe[1924] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\DAEMON Tools\daemon.exe[1924] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\DAEMON Tools\daemon.exe[1924] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe[1944] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe[1944] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe[1944] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe[1944] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe[1944] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe[1944] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\CTSVCCDA.EXE[1956] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\CTSVCCDA.EXE[1956] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\CTSVCCDA.EXE[1956] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\CTSVCCDA.EXE[1956] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\CTSVCCDA.EXE[1956] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\CTSVCCDA.EXE[1956] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe[1972] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe[1972] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe[1972] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe[1972] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe[1972] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe[1972] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLService.exe[2020] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLService.exe[2020] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLService.exe[2020] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLService.exe[2020] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLService.exe[2020] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\CyberLink\Shared Files\CLML_NTService\CLMLService.exe[2020] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE[2040] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE[2040] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE[2040] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE[2040] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE[2040] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\Fælles filer\Microsoft Shared\VS7DEBUG\MDM.EXE[2040] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\CyberLink\PowerCinema\Kernel\TV\CLSched.exe[2064] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\CyberLink\PowerCinema\Kernel\TV\CLSched.exe[2064] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\CyberLink\PowerCinema\Kernel\TV\CLSched.exe[2064] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\CyberLink\PowerCinema\Kernel\TV\CLSched.exe[2064] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\CyberLink\PowerCinema\Kernel\TV\CLSched.exe[2064] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\CyberLink\PowerCinema\Kernel\TV\CLSched.exe[2064] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\DVD tools\utorrent.exe[2088] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\DVD tools\utorrent.exe[2088] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\DVD tools\utorrent.exe[2088] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\DVD tools\utorrent.exe[2088] user32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\DVD tools\utorrent.exe[2088] user32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\DVD tools\utorrent.exe[2088] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[2160] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[2160] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[2160] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[2160] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[2160] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\ctfmon.exe[2160] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe[2168] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe[2168] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe[2168] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe[2168] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe[2168] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\Fælles filer\Ahead\Lib\NMBgMonitor.exe[2168] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\MSN Messenger\msnmsgr.exe[2192] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\MSN Messenger\msnmsgr.exe[2192] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\MSN Messenger\msnmsgr.exe[2192] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\MSN Messenger\msnmsgr.exe[2192] kernel32.dll!SetUnhandledExceptionFilter 7C84479D 5 Bytes JMP 004E12D0 C:\Programmer\MSN Messenger\msnmsgr.exe
.text C:\Programmer\MSN Messenger\msnmsgr.exe[2192] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\MSN Messenger\msnmsgr.exe[2192] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\MSN Messenger\msnmsgr.exe[2192] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe[2244] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe[2244] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe[2244] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe[2244] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe[2244] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\SUPERAntiSpyware\SUPERAntiSpyware.exe[2244] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\WinPFind3u\WinPFind3U.exe[2256] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\WinPFind3u\WinPFind3U.exe[2256] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\WinPFind3u\WinPFind3U.exe[2256] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\WinPFind3u\WinPFind3U.exe[2256] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Documents and Settings\Ejer\Skrivebord\WinPFind3u\WinPFind3U.exe[2256] user32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\WinPFind3u\WinPFind3U.exe[2256] user32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Documents and Settings\Ejer\Skrivebord\WinPFind3u\WinPFind3U.exe[2256] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\Canon\CD-LabelPrint\CDLabelPrint.exe[2280] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\Canon\CD-LabelPrint\CDLabelPrint.exe[2280] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\Canon\CD-LabelPrint\CDLabelPrint.exe[2280] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\Canon\CD-LabelPrint\CDLabelPrint.exe[2280] kernel32.dll!FreeLibrary + 15 7C80ABF3 4 Bytes [ 45, 54, 7F, E2 ]
.text C:\Programmer\Canon\CD-LabelPrint\CDLabelPrint.exe[2280] user32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\Canon\CD-LabelPrint\CDLabelPrint.exe[2280] user32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\Canon\CD-LabelPrint\CDLabelPrint.exe[2280] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe[2368] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe[2368] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe[2368] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe[2368] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe[2368] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\Programmer\Microsoft AntiSpyware\gcasDtServ.exe[2368] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\alg.exe[2800] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\alg.exe[2800] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\alg.exe[2800] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\alg.exe[2800] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\alg.exe[2800] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\alg.exe[2800] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\Crazy Browser\Crazy Browser.exe[2964] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\Programmer\Crazy Browser\Crazy Browser.exe[2964] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\Programmer\Crazy Browser\Crazy Browser.exe[2964] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\Programmer\Crazy Browser\Crazy Browser.exe[2964] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\Programmer\Crazy Browser\Crazy Browser.exe[2964] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\Programmer\Crazy Browser\Crazy Browser.exe[2964] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\WgaTray.exe[3032] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes [ FF, 25, 1E, 00, 08, 5F ]
.text C:\WINDOWS\system32\WgaTray.exe[3032] kernel32.dll!CreateProcessW 7C802332 6 Bytes [ FF, 25, 1E, 00, 16, 5F ]
.text C:\WINDOWS\system32\WgaTray.exe[3032] kernel32.dll!CreateProcessA 7C802367 6 Bytes [ FF, 25, 1E, 00, 12, 5F ]
.text C:\WINDOWS\system32\WgaTray.exe[3032] USER32.dll!SetWindowsHookExW 77D4E4AF 6 Bytes [ FF, 25, 1E, 00, 0F, 5F ]
.text C:\WINDOWS\system32\WgaTray.exe[3032] USER32.dll!SetWindowsHookExA 77D511E9 6 Bytes [ FF, 25, 1E, 00, 0B, 5F ]
.text C:\WINDOWS\system32\WgaTray.exe[3032] GDI32.dll!Escape 77F26926 6 Bytes [ FF, 25, 1E, 00, 05, 5F ]
.text C:\WINDOWS\system32\WgaTray.exe[3032] WININET.dll!InternetErrorDlg 7721C31D 5 Bytes JMP 0101211B C:\WINDOWS\system32\WgaTray.exe
---- Devices - GMER 1.0.12 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 873611D8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 873611D8
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 86DF2440
Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 86DF2440
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CREATE 85F6D708
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CLOSE 85F6D708
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_READ 85F6D708
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_WRITE 85F6D708
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_QUERY_INFORMATION 85F6D708
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_SET_INFORMATION 85F6D708
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_QUERY_VOLUME_INFORMATION 85F6D708
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_DIRECTORY_CONTROL 85F6D708
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_FILE_SYSTEM_CONTROL 85F6D708
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_DEVICE_CONTROL 85F6D708
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_LOCK_CONTROL 85F6D708
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_CLEANUP 85F6D708
Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_PNP 85F6D708
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CREATE 85F6D708
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CLOSE 85F6D708
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_READ 85F6D708
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_WRITE 85F6D708
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_QUERY_INFORMATION 85F6D708
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_SET_INFORMATION 85F6D708
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_QUERY_VOLUME_INFORMATION 85F6D708
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_DIRECTORY_CONTROL 85F6D708
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_FILE_SYSTEM_CONTROL 85F6D708
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_DEVICE_CONTROL 85F6D708
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_LOCK_CONTROL 85F6D708
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_CLEANUP 85F6D708
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_PNP 85F6D708
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F7DAC85A] avgtdi.sys
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CREATE 870DF980
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CLOSE 870DF980
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 870DF980
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 870DF980
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_POWER 870DF980
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 870DF980
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_PNP 870DF980
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 873D21D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 873D21D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 873D21D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 873D21D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 873D21D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 873D21D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 873D21D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 873D21D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 873D21D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 873D21D8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 873D21D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 873D21D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 873D21D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 873D21D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 873D21D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 873D21D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 873D21D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 873D21D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 873D21D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 873D21D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 873D21D8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 873D21D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 873D21D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 873D21D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 873D21D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 873D21D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 873D21D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 873D21D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 873D21D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 873D21D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 873D21D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 873D21D8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 873D21D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 873D21D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 873D21D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 873D21D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 873D21D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 873D21D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 873D21D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 873D21D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 873D21D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 873D21D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 873D21D8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 873D21D8
Device \Driver\usbohci \Device\USBPDO-1 IRP_MJ_CREATE 870DF980
Device \Driver\usbohci \Device\USBPDO-1 IRP_MJ_CLOSE 870DF980
Device \Driver\usbohci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 870DF980
Device \Driver\usbohci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 870DF980
Device \Driver\usbohci \Device\USBPDO-1 IRP_MJ_POWER 870DF980
Device \Driver\usbohci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 870DF980
Device \Driver\usbohci \Device\USBPDO-1 IRP_MJ_PNP 870DF980
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_CREATE 8708B980
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_CLOSE 8708B980
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL 8708B980
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8708B980
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_POWER 8708B980
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL 8708B980
Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_PNP 8708B980
Device \Driver\00000048 \Device\00000060 IRP_MJ_POWER [F7745C7E] sptd.sys
Device \Driver\00000048 \Device\00000060 IRP_MJ_SYSTEM_CONTROL [F775F2A2] sptd.sys
Device \Driver\00000048 \Device\00000060 IRP_MJ_PNP [F7760228] sptd.sys
Device \Driver\usbohci \Device\USBPDO-3 IRP_MJ_CREATE 870DF980
Device \Driver\usbohci \Device\USBPDO-3 IRP_MJ_CLOSE 870DF980
Device \Driver\usbohci \Device\USBPDO-3 IRP_MJ_DEVICE_CONTROL 870DF980
Device \Driver\usbohci \Device\USBPDO-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 870DF980
Device \Driver\usbohci \Device\USBPDO-3 IRP_MJ_POWER 870DF980
Device \Driver\usbohci \Device\USBPDO-3 IRP_MJ_SYSTEM_CONTROL 870DF980
Device \Driver\usbohci \Device\USBPDO-3 IRP_MJ_PNP 870DF980
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F7DAC85A] avgtdi.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 873631D8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 870D17A0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 870D17A0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 870D17A0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 870D17A0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 870D17A0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 870D17A0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 870D17A0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 870D17A0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 870D17A0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 870D17A0
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 870D17A0
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_READ 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_WRITE 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLEANUP 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_POWER 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL 873631D8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_PNP 873631D8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 870D17A0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 870D17A0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 870D17A0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 870D17A0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 870D17A0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 870D17A0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 870D17A0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 870D17A0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 870D17A0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 870D17A0
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 870D17A0
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 873621D8
Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 873621D8
Device \Driver\atapi \Device