![]() |
Antivirus Blocking Rules vorweg , ich bin pc-blond also habt bitte nachsehen mit mir. Danke Problem: Habe Spyhunter 4 heruntergeladen um meinen PC auf Malware zu prüfen. Resultat 10 Infektionen 1.Antivirus Blocking Rules (1 Infektion) wird als sehr gefährlich angezeigt 2.Winload Toolbar (9 Infektionen ) mittlerer Wert Ich möchte Spyhunter nicht unbedingt kaufen um diese Probleme zu lösen könnt ihr mir helfen ? (PC- Blondine , bitte berücksichtigen *g) Vielen Dank im Vorfeld , dunkelbunt |
Hallo, den SpyHunter kannst du grad wieder deinstallieren, der ist grosser Mist. Wenn du deinen Rechner nach Malware untersuchen lassen willst, dann arbeite bitte diese Anleitung ab und poste die resultierenden Logfiles hier. |
defogger_disable by jpshortstuff (23.02.10.1) Log created at 17:38 on 20/08/2013 (peppermint) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-08-2013 03 FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 20-08-2013 03 Gmer folgt ..... |
GMER 2.1.19163 - GMER - Rootkit Detector and Remover Rootkit scan 2013-08-20 18:29:12 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 rev. 0,00MB Running: gmer_2.1.19163.exe; Driver: C:\Users\PEPPER~1\AppData\Local\Temp\kfriqpob.sys ---- System - GMER 2.1 ---- SSDT \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys ZwCreateSection [0x971F9700] SSDT 91C53CA8 ZwRequestWaitReplyPort SSDT 91C53CA3 ZwSetContextThread SSDT 91C53CAD ZwSetSecurityObject SSDT 91C53CB2 ZwSystemDebugControl SSDT 91C53C3F ZwTerminateProcess Code 8EB18BFC ZwTraceEvent Code 8EB18BFB NtTraceEvent ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwRollbackEnlistment + 142D 82C7CA15 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82CB6212 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text ntkrnlpa.exe!KeRemoveQueueEx + 11F7 82CBD58C 4 Bytes [00, 97, 1F, 97] .text ntkrnlpa.exe!KeRemoveQueueEx + 1553 82CBD8E8 4 Bytes [A8, 3C, C5, 91] .text ntkrnlpa.exe!KeRemoveQueueEx + 1597 82CBD92C 4 Bytes [A3, 3C, C5, 91] .text ntkrnlpa.exe!KeRemoveQueueEx + 1613 82CBD9A8 4 Bytes [AD, 3C, C5, 91] {LODSD ; CMP AL, 0xc5; XCHG ECX, EAX} .text ntkrnlpa.exe!KeRemoveQueueEx + 1667 82CBD9FC 4 Bytes [B2, 3C, C5, 91] .text ... .text ntkrnlpa.exe!NtTraceEvent 82D06AE2 5 Bytes JMP 8EB18C00 ? System32\drivers\ekbemwb.sys Das System kann den angegebenen Pfad nicht finden. ! ? C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys Das System kann die angegebene Datei nicht finden. ! ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!RtlAdjustPrivilege 7785BC4A 5 Bytes JMP 00F61FA1 C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtAlpcConnectPort 77895348 5 Bytes JMP 73EA7770 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtAlpcCreatePort 77895358 5 Bytes JMP 73EA75F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtAlpcImpersonateClientOfPort 778953F8 5 Bytes JMP 73EA6040 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtAlpcQueryInformation 77895428 5 Bytes JMP 73EA5D80 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtAlpcQueryInformationMessage 77895438 5 Bytes JMP 73EA5DB0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtAlpcSendWaitReceivePort 77895458 5 Bytes JMP 73EA66C0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtClose 77895508 5 Bytes JMP 73E9C690 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtConnectPort 77895598 5 Bytes JMP 73EA71B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtCreateEvent 778955E8 5 Bytes JMP 73EA7C50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtCreateFile 77895608 5 Bytes JMP 73E9CF20 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtCreateKey 77895648 5 Bytes JMP 73EAC3E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtCreateMailslotFile 77895678 5 Bytes JMP 73E99EE0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtCreateMutant 77895688 5 Bytes JMP 73EA7FF0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtCreateNamedPipeFile 77895698 5 Bytes JMP 73E9A080 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtCreatePort 778956B8 5 Bytes JMP 73EA7040 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtCreateSection 77895728 5 Bytes JMP 73EA8700 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtCreateSemaphore 77895738 5 Bytes JMP 73EA8360 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtDeleteFile 77895848 5 Bytes JMP 73E95B50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtDeleteKey 77895858 5 Bytes JMP 73EAD000 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtDeleteValueKey 77895888 5 Bytes JMP 73EADD80 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtDeviceIoControlFile 77895898 5 Bytes JMP 73E9A280 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtEnumerateKey 77895928 5 Bytes JMP 73EAD3B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtEnumerateValueKey 77895958 5 Bytes JMP 73EAD9C0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtFsControlFile 77895A48 5 Bytes JMP 73E9C530 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtImpersonateClientOfPort 77895B08 5 Bytes JMP 73EA6010 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtLoadDriver 77895B98 5 Bytes JMP 73EAF650 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtLoadKey 77895BA8 5 Bytes JMP 73EAB610 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtMapViewOfSection 77895C68 5 Bytes JMP 73EAF8C0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtNotifyChangeKey 77895CA8 5 Bytes JMP 73EAC070 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtNotifyChangeMultipleKeys 77895CB8 5 Bytes JMP 73EAB250 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtOpenEvent 77895CF8 5 Bytes JMP 73EA7E40 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtOpenFile 77895D18 5 Bytes JMP 73E9E520 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtOpenKey 77895D48 5 Bytes JMP 73EACF80 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtOpenKeyEx 77895D58 5 Bytes JMP 73EACFB0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtOpenMutant 77895D98 5 Bytes JMP 73EA81B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtOpenSection 77895E08 5 Bytes JMP 73EA8930 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtOpenSemaphore 77895E18 5 Bytes JMP 73EA8550 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtQueryAttributesFile 77895F78 5 Bytes JMP 73E95940 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtQueryDirectoryFile 77895FD8 5 Bytes JMP 73E9A410 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtQueryFullAttributesFile 77896028 5 Bytes JMP 73E99450 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtQueryInformationFile 77896058 5 Bytes JMP 73E9DEA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtQueryKey 77896128 5 Bytes JMP 73EAD020 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtQueryMultipleValueKey 77896148 5 Bytes JMP 73EADB50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtQueryValueKey 77896288 5 Bytes JMP 73EAD780 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtQueryVolumeInformationFile 778962A8 5 Bytes JMP 73E9C870 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtReadFile 778962F8 5 Bytes JMP 73E93220 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtRenameKey 77896408 5 Bytes JMP 73EAB5E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtRequestWaitReplyPort 77896498 5 Bytes JMP 73EA64E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtSaveKey 77896538 5 Bytes JMP 73E8F690 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtSecureConnectPort 77896568 5 Bytes JMP 73EA73B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtSetInformationFile 77896678 5 Bytes JMP 73E9E2A0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtSetInformationProcess 778966B8 5 Bytes JMP 00F61FCE C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtSetValueKey 77896848 5 Bytes JMP 73EABF30 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!NtWriteFile 77896AA8 5 Bytes JMP 73E932F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!LdrUnloadDll 778AC8DE 3 Bytes JMP 73EAF400 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!LdrUnloadDll + 4 778AC8E2 1 Byte [FC] .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!RtlGetFullPathName_UEx 778B5D4E 5 Bytes JMP 73E9B020 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!RtlSetCurrentDirectory_U 778C4ECD 5 Bytes JMP 73E9ADE0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ntdll.dll!RtlGetCurrentDirectory_U 778C4F90 5 Bytes JMP 73E9ABA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] kernel32.dll!MoveFileWithProgressW 77688DD4 5 Bytes JMP 73E93F80 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] kernel32.dll!ReplaceFile 776A1708 5 Bytes JMP 73E9E490 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!StartServiceW 75E37974 5 Bytes JMP 00F61D52 C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!QueryServiceStatusEx 75E3798C 5 Bytes JMP 00F61C46 C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!RegConnectRegistryW 75E38F01 5 Bytes JMP 73E89180 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!StartServiceCtrlDispatcherW 75E3A965 5 Bytes JMP 00F61B5A C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!SetServiceStatus 75E3C7A6 5 Bytes JMP 00F61A5C C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!OpenServiceW 75E3CA4C 5 Bytes JMP 00F61B83 C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!LookupAccountNameW 75E3E276 5 Bytes JMP 73E890B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!QueryServiceStatus 75E42A86 5 Bytes JMP 00F61CFE C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!CloseServiceHandle 75E4369C 5 Bytes JMP 00F61C16 C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!ControlService 75E57144 5 Bytes JMP 00F61D92 C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!CredWriteA 75E77051 5 Bytes JMP 73E8D780 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!CredWriteW 75E77109 5 Bytes JMP 73E8D140 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!CredReadA 75E771C1 5 Bytes JMP 73E8D840 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!CredReadW 75E772A1 5 Bytes JMP 73E8D1D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!CredEnumerateA 75E77381 5 Bytes JMP 73E8D8A0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!CredEnumerateW 75E77481 5 Bytes JMP 73E8D530 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!CredWriteDomainCredentialsA 75E77581 5 Bytes JMP 73E8D7B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!CredWriteDomainCredentialsW 75E77661 5 Bytes JMP 73E8D2B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!CredReadDomainCredentialsA 75E77741 5 Bytes JMP 73E8D870 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!CredReadDomainCredentialsW 75E77841 5 Bytes JMP 73E8D3A0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!CredDeleteA 75E77941 5 Bytes JMP 73E8D810 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!CredDeleteW 75E779F1 5 Bytes JMP 73E8D4E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!CredRenameA 75E77AA1 5 Bytes JMP 73E8D750 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!GetEffectiveRightsFromAclW 75E817B1 5 Bytes JMP 73E892B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!RegConnectRegistryA 75E8EF59 5 Bytes JMP 73E89140 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ADVAPI32.dll!EnumServicesStatusA + 3 75E92024 2 Bytes [02, FE] {ADD BH, DH} .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!RegisterClassExA 76586293 5 Bytes JMP 73EA0CA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!RegisterDeviceNotificationA 76586C53 5 Bytes JMP 73E9F800 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!GetWindowTextA 76586EED 5 Bytes JMP 73EA1AA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!FindWindowExA 76586F69 5 Bytes JMP 73EA1FF0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!GetClassInfoExA 76586FD9 5 Bytes JMP 73EA1040 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!GetClassInfoA 76587158 5 Bytes JMP 73EA1120 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SetParent 76588314 5 Bytes JMP 73E9F620 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SetWindowLongA 76588BA3 5 Bytes JMP 73EA2940 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!MoveWindow 76588D29 5 Bytes JMP 73E9F660 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!UnregisterClassA 76588D70 5 Bytes JMP 73EA0F70 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!FindWindowA 76588FF3 5 Bytes JMP 73EA1EC0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!GetWindowLongA 7658A95E 5 Bytes JMP 73EA2750 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SendMessageA 7658AD60 5 Bytes JMP 73EA2ED0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!UnhookWindowsHookEx 7658ADF9 5 Bytes JMP 73EA3620 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!FindWindowW 7658AE0D 5 Bytes JMP 73EA1E30 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!PostMessageA 7658B446 5 Bytes JMP 73EA31F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!EnumDesktopWindows 7658B4C7 5 Bytes JMP 73EA1D10 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!EnumThreadWindows 7658B712 5 Bytes JMP 73EA1CE0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!GetWindowTextW 7658B8C5 5 Bytes JMP 73EA1A70 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!UnregisterClassW 7658B9AE 2 Bytes JMP 73EA0F10 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!UnregisterClassW + 3 7658B9B1 2 Bytes [91, FD] {XCHG ECX, EAX; STD } .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!DefWindowProcA 7658BB1C 5 Bytes JMP 73E9F560 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!RegisterClassA 7658BC6A 5 Bytes JMP 73EA0E40 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!CreateWindowExA 7658BF40 5 Bytes JMP 73E9F280 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SendNotifyMessageW 7658C88A 5 Bytes JMP 73EA3190 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SetWindowsHookExW 7658E30C 5 Bytes JMP 73EA3940 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SendMessageTimeoutW 7658E459 5 Bytes JMP 73EA3080 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!CreateWindowExW 7658EC7C 5 Bytes JMP 73E9F160 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!RegisterClassW 7658ED4A 5 Bytes JMP 73EA0D70 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!RegisterClassExW 76590162 5 Bytes JMP 73EA0BD0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!GetClassInfoExW 7659095E 5 Bytes JMP 73EA0FD0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!GetClassInfoW 76590AC2 5 Bytes JMP 73EA10B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SetWindowPos 76591BC4 5 Bytes JMP 73E9F6B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!EnumChildWindows 76592948 5 Bytes JMP 73EA1CB0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!GetClassNameW 76592A29 5 Bytes JMP 73EA02F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!DispatchMessageA 76592E32 5 Bytes JMP 73EA2BA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!GetShellWindow 76592FCB 5 Bytes JMP 73EA2090 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!EnumWindows 7659375B 5 Bytes JMP 73EA1C60 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SetWindowLongW 76594449 5 Bytes JMP 73EA28B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!PostMessageW 7659447B 5 Bytes JMP 73EA3270 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!DefWindowProcW 7659507D 5 Bytes JMP 73E9F4F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SendMessageW 76595539 5 Bytes JMP 73EA2F60 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!GetPropW 76595BBE 5 Bytes JMP 73EA2470 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SetPropW 76595DC5 5 Bytes JMP 73EA2530 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!RemovePropW 76595FE1 5 Bytes JMP 73EA25D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!GetWindowLongW 765961B8 5 Bytes JMP 73EA26D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!DispatchMessageW 7659CC61 5 Bytes JMP 73EA2BF0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!NotifyWinEvent + 5D2 7659D590 4 Bytes [B0, 07, EA, 73] .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!CreateDialogParamA 765A1F42 5 Bytes JMP 73EA4600 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!DialogBoxParamW 765A3B9B 5 Bytes JMP 73EA4640 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SendNotifyMessageA 765A493C 5 Bytes JMP 73EA3130 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!CreateDialogIndirectParamA 765A721D 5 Bytes JMP 73EA4530 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!CreateDialogIndirectParamW 765AEA10 5 Bytes JMP 73EA4500 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!GetClassNameA 765B2445 5 Bytes JMP 73EA03D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!RemovePropA 765B2551 5 Bytes JMP 73EA2610 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SetPropA 765B28E5 5 Bytes JMP 73EA2580 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!GetPropA 765B2B61 5 Bytes JMP 73EA24F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!DialogBoxIndirectParamAorW 765B3B40 5 Bytes JMP 73EA44B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!DialogBoxIndirectParamW 765B3B7F 5 Bytes JMP 73EA4560 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!CreateDialogIndirectParamAorW 765B5327 5 Bytes JMP 73EA4450 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!CreateDialogParamW 765B5630 5 Bytes JMP 73EA45C0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SetWindowsHookExA 765B6D0C 5 Bytes JMP 73EA38F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SendMessageTimeoutA 765B6DA9 5 Bytes JMP 73EA3020 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!FindWindowExW 765B712B 5 Bytes JMP 73EA1F50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SetDoubleClickTime 765CC1CB 5 Bytes JMP 73E9F820 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!SwapMouseButton 765CC1FB 5 Bytes JMP 73E9F820 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!DialogBoxParamA 765CCF42 5 Bytes JMP 73EA4680 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!DialogBoxIndirectParamA 765CD274 5 Bytes JMP 73EA4590 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!EndTask 765CFD66 5 Bytes JMP 73E9F770 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] USER32.dll!ExitWindowsEx 765D06C7 5 Bytes JMP 73E9F5D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] GDI32.dll!EnumFontFamiliesExW 77A3CE94 5 Bytes JMP 73E9EF50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] GDI32.dll!GdiAddFontResourceW 77A3E1F1 5 Bytes JMP 73E9EB00 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] GDI32.dll!EnumFontFamiliesExA 77A50B50 5 Bytes JMP 73E9EF30 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] GDI32.dll!CreateScalableFontResourceW 77A5E817 5 Bytes JMP 73E9ECF0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] GDI32.dll!RemoveFontResourceExW 77A5EC5C 5 Bytes JMP 73E9EB90 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] GDI32.dll!GetFontResourceInfoW 77A5EE2D 5 Bytes JMP 73E9EC10 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ole32.dll!CoMarshalInterface 7644EF03 5 Bytes JMP 73E8A800 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ole32.dll!CoUnmarshalInterface 7644F150 5 Bytes JMP 73E8C4E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ole32.dll!CoGetClassObject 764554AD 5 Bytes JMP 73E8C0F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ole32.dll!CoCreateInstance 76469D0B 5 Bytes JMP 73E8C270 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ole32.dll!CoCreateInstanceEx 76469D4E 5 Bytes JMP 73E8C370 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe[1080] ole32.dll!CoGetObject 7647B68D 5 Bytes JMP 73E8C1A0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!RtlAdjustPrivilege 7785BC4A 5 Bytes JMP 013123C1 C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtAlpcConnectPort 77895348 5 Bytes JMP 73EA7770 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtAlpcCreatePort 77895358 5 Bytes JMP 73EA75F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtAlpcImpersonateClientOfPort 778953F8 5 Bytes JMP 73EA6040 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtAlpcQueryInformation 77895428 5 Bytes JMP 73EA5D80 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtAlpcQueryInformationMessage 77895438 5 Bytes JMP 73EA5DB0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtAlpcSendWaitReceivePort 77895458 5 Bytes JMP 73EA66C0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtClose 77895508 5 Bytes JMP 73E9C690 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtConnectPort 77895598 5 Bytes JMP 73EA71B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtCreateEvent 778955E8 5 Bytes JMP 73EA7C50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtCreateFile 77895608 5 Bytes JMP 73E9CF20 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtCreateKey 77895648 5 Bytes JMP 73EAC3E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtCreateMailslotFile 77895678 5 Bytes JMP 73E99EE0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtCreateMutant 77895688 5 Bytes JMP 73EA7FF0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtCreateNamedPipeFile 77895698 5 Bytes JMP 73E9A080 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtCreatePort 778956B8 5 Bytes JMP 73EA7040 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtCreateSection 77895728 5 Bytes JMP 73EA8700 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtCreateSemaphore 77895738 5 Bytes JMP 73EA8360 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtDeleteFile 77895848 5 Bytes JMP 73E95B50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtDeleteKey 77895858 5 Bytes JMP 73EAD000 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtDeleteValueKey 77895888 5 Bytes JMP 73EADD80 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtDeviceIoControlFile 77895898 5 Bytes JMP 73E9A280 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtEnumerateKey 77895928 5 Bytes JMP 73EAD3B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtEnumerateValueKey 77895958 5 Bytes JMP 73EAD9C0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtFsControlFile 77895A48 5 Bytes JMP 73E9C530 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtImpersonateClientOfPort 77895B08 5 Bytes JMP 73EA6010 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtLoadDriver 77895B98 5 Bytes JMP 73EAF650 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtLoadKey 77895BA8 5 Bytes JMP 73EAB610 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtMapViewOfSection 77895C68 5 Bytes JMP 73EAF8C0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtNotifyChangeKey 77895CA8 5 Bytes JMP 73EAC070 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtNotifyChangeMultipleKeys 77895CB8 5 Bytes JMP 73EAB250 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtOpenEvent 77895CF8 5 Bytes JMP 73EA7E40 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtOpenFile 77895D18 5 Bytes JMP 73E9E520 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtOpenKey 77895D48 5 Bytes JMP 73EACF80 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtOpenKeyEx 77895D58 5 Bytes JMP 73EACFB0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtOpenMutant 77895D98 5 Bytes JMP 73EA81B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtOpenSection 77895E08 5 Bytes JMP 73EA8930 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtOpenSemaphore 77895E18 5 Bytes JMP 73EA8550 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtQueryAttributesFile 77895F78 5 Bytes JMP 73E95940 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtQueryDirectoryFile 77895FD8 5 Bytes JMP 73E9A410 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtQueryFullAttributesFile 77896028 5 Bytes JMP 73E99450 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtQueryInformationFile 77896058 5 Bytes JMP 73E9DEA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtQueryKey 77896128 5 Bytes JMP 73EAD020 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtQueryMultipleValueKey 77896148 5 Bytes JMP 73EADB50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtQueryValueKey 77896288 5 Bytes JMP 73EAD780 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtQueryVolumeInformationFile 778962A8 5 Bytes JMP 73E9C870 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtReadFile 778962F8 5 Bytes JMP 73E93220 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtRenameKey 77896408 5 Bytes JMP 73EAB5E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtRequestWaitReplyPort 77896498 5 Bytes JMP 73EA64E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtSaveKey 77896538 5 Bytes JMP 73E8F690 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtSecureConnectPort 77896568 5 Bytes JMP 73EA73B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtSetInformationFile 77896678 5 Bytes JMP 73E9E2A0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtSetInformationProcess 778966B8 5 Bytes JMP 013123EE C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtSetValueKey 77896848 5 Bytes JMP 73EABF30 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!NtWriteFile 77896AA8 5 Bytes JMP 73E932F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!LdrUnloadDll 778AC8DE 3 Bytes JMP 73EAF400 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!LdrUnloadDll + 4 778AC8E2 1 Byte [FC] .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!RtlGetFullPathName_UEx 778B5D4E 5 Bytes JMP 73E9B020 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!RtlSetCurrentDirectory_U 778C4ECD 5 Bytes JMP 73E9ADE0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ntdll.dll!RtlGetCurrentDirectory_U 778C4F90 5 Bytes JMP 73E9ABA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] kernel32.dll!MoveFileWithProgressW 77688DD4 5 Bytes JMP 73E93F80 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] kernel32.dll!ReplaceFile 776A1708 5 Bytes JMP 73E9E490 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!StartServiceW 75E37974 5 Bytes JMP 01312172 C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!QueryServiceStatusEx 75E3798C 5 Bytes JMP 01312066 C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!RegConnectRegistryW 75E38F01 5 Bytes JMP 73E89180 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!StartServiceCtrlDispatcherW 75E3A965 5 Bytes JMP 01311F7A C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!SetServiceStatus 75E3C7A6 5 Bytes JMP 01311E7C C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!OpenServiceW 75E3CA4C 2 Bytes JMP 01311FA3 C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!OpenServiceW + 3 75E3CA4F 2 Bytes [4D, 8B] .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!LookupAccountNameW 75E3E276 5 Bytes JMP 73E890B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!QueryServiceStatus 75E42A86 5 Bytes JMP 0131211E C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!CloseServiceHandle 75E4369C 5 Bytes JMP 01312036 C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!RegOpenKeyExW 75E4468D 5 Bytes JMP 013127BE C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!RegQueryValueExW 75E446AD 5 Bytes JMP 01312845 C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!ControlService 75E57144 5 Bytes JMP 013121B2 C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!CredWriteA 75E77051 5 Bytes JMP 73E8D780 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!CredWriteW 75E77109 5 Bytes JMP 73E8D140 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!CredReadA 75E771C1 5 Bytes JMP 73E8D840 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!CredReadW 75E772A1 5 Bytes JMP 73E8D1D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!CredEnumerateA 75E77381 5 Bytes JMP 73E8D8A0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!CredEnumerateW 75E77481 5 Bytes JMP 73E8D530 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!CredWriteDomainCredentialsA 75E77581 5 Bytes JMP 73E8D7B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!CredWriteDomainCredentialsW 75E77661 5 Bytes JMP 73E8D2B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!CredReadDomainCredentialsA 75E77741 5 Bytes JMP 73E8D870 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!CredReadDomainCredentialsW 75E77841 5 Bytes JMP 73E8D3A0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!CredDeleteA 75E77941 5 Bytes JMP 73E8D810 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!CredDeleteW 75E779F1 5 Bytes JMP 73E8D4E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!CredRenameA 75E77AA1 5 Bytes JMP 73E8D750 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!GetEffectiveRightsFromAclW 75E817B1 5 Bytes JMP 73E892B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!RegConnectRegistryA 75E8EF59 5 Bytes JMP 73E89140 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ADVAPI32.dll!EnumServicesStatusA + 3 75E92024 2 Bytes [02, FE] {ADD BH, DH} .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!RegisterClassExA 76586293 5 Bytes JMP 73EA0CA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!RegisterDeviceNotificationA 76586C53 5 Bytes JMP 73E9F800 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!GetWindowTextA 76586EED 5 Bytes JMP 73EA1AA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!FindWindowExA 76586F69 5 Bytes JMP 73EA1FF0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!GetClassInfoExA 76586FD9 5 Bytes JMP 73EA1040 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!GetClassInfoA 76587158 5 Bytes JMP 73EA1120 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SetParent 76588314 5 Bytes JMP 73E9F620 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SetWindowLongA 76588BA3 5 Bytes JMP 73EA2940 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!MoveWindow 76588D29 5 Bytes JMP 73E9F660 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!UnregisterClassA 76588D70 5 Bytes JMP 73EA0F70 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!FindWindowA 76588FF3 5 Bytes JMP 73EA1EC0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!GetWindowLongA 7658A95E 5 Bytes JMP 73EA2750 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SendMessageA 7658AD60 5 Bytes JMP 73EA2ED0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!UnhookWindowsHookEx 7658ADF9 5 Bytes JMP 73EA3620 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!FindWindowW 7658AE0D 5 Bytes JMP 73EA1E30 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!PostMessageA 7658B446 5 Bytes JMP 73EA31F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!EnumDesktopWindows 7658B4C7 5 Bytes JMP 73EA1D10 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!EnumThreadWindows 7658B712 5 Bytes JMP 73EA1CE0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!GetWindowTextW 7658B8C5 5 Bytes JMP 73EA1A70 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!UnregisterClassW 7658B9AE 2 Bytes JMP 73EA0F10 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!UnregisterClassW + 3 7658B9B1 2 Bytes [91, FD] {XCHG ECX, EAX; STD } .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!DefWindowProcA 7658BB1C 5 Bytes JMP 73E9F560 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!RegisterClassA 7658BC6A 5 Bytes JMP 73EA0E40 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!CreateWindowExA 7658BF40 5 Bytes JMP 73E9F280 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SendNotifyMessageW 7658C88A 5 Bytes JMP 73EA3190 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SetWindowsHookExW 7658E30C 5 Bytes JMP 73EA3940 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SendMessageTimeoutW 7658E459 5 Bytes JMP 73EA3080 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!CreateWindowExW 7658EC7C 5 Bytes JMP 73E9F160 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!RegisterClassW 7658ED4A 5 Bytes JMP 73EA0D70 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!RegisterClassExW 76590162 5 Bytes JMP 73EA0BD0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!GetClassInfoExW 7659095E 5 Bytes JMP 73EA0FD0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!GetClassInfoW 76590AC2 5 Bytes JMP 73EA10B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SetWindowPos 76591BC4 5 Bytes JMP 73E9F6B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!EnumChildWindows 76592948 5 Bytes JMP 73EA1CB0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!GetClassNameW 76592A29 5 Bytes JMP 73EA02F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!DispatchMessageA 76592E32 5 Bytes JMP 73EA2BA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!GetShellWindow 76592FCB 5 Bytes JMP 73EA2090 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!EnumWindows 7659375B 5 Bytes JMP 73EA1C60 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SetWindowLongW 76594449 5 Bytes JMP 73EA28B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!PostMessageW 7659447B 5 Bytes JMP 73EA3270 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!DefWindowProcW 7659507D 5 Bytes JMP 73E9F4F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SendMessageW 76595539 5 Bytes JMP 73EA2F60 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!GetPropW 76595BBE 5 Bytes JMP 73EA2470 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SetPropW 76595DC5 5 Bytes JMP 73EA2530 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!RemovePropW 76595FE1 5 Bytes JMP 73EA25D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!GetWindowLongW 765961B8 5 Bytes JMP 73EA26D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!DispatchMessageW 7659CC61 5 Bytes JMP 73EA2BF0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!NotifyWinEvent + 5D2 7659D590 4 Bytes [B0, 07, EA, 73] .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!CreateDialogParamA 765A1F42 5 Bytes JMP 73EA4600 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!DialogBoxParamW 765A3B9B 5 Bytes JMP 73EA4640 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SendNotifyMessageA 765A493C 5 Bytes JMP 73EA3130 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!CreateDialogIndirectParamA 765A721D 5 Bytes JMP 73EA4530 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!CreateDialogIndirectParamW 765AEA10 5 Bytes JMP 73EA4500 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!GetClassNameA 765B2445 5 Bytes JMP 73EA03D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!RemovePropA 765B2551 5 Bytes JMP 73EA2610 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SetPropA 765B28E5 5 Bytes JMP 73EA2580 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!GetPropA 765B2B61 5 Bytes JMP 73EA24F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!DialogBoxIndirectParamAorW 765B3B40 5 Bytes JMP 73EA44B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!DialogBoxIndirectParamW 765B3B7F 5 Bytes JMP 73EA4560 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!CreateDialogIndirectParamAorW 765B5327 5 Bytes JMP 73EA4450 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!CreateDialogParamW 765B5630 5 Bytes JMP 73EA45C0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SetWindowsHookExA 765B6D0C 5 Bytes JMP 73EA38F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SendMessageTimeoutA 765B6DA9 5 Bytes JMP 73EA3020 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!FindWindowExW 765B712B 5 Bytes JMP 73EA1F50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SetDoubleClickTime 765CC1CB 5 Bytes JMP 73E9F820 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!SwapMouseButton 765CC1FB 5 Bytes JMP 73E9F820 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!DialogBoxParamA 765CCF42 5 Bytes JMP 73EA4680 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!DialogBoxIndirectParamA 765CD274 5 Bytes JMP 73EA4590 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!EndTask 765CFD66 5 Bytes JMP 73E9F770 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] USER32.dll!ExitWindowsEx 765D06C7 5 Bytes JMP 73E9F5D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] GDI32.dll!EnumFontFamiliesExW 77A3CE94 5 Bytes JMP 73E9EF50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] GDI32.dll!GdiAddFontResourceW 77A3E1F1 5 Bytes JMP 73E9EB00 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] GDI32.dll!EnumFontFamiliesExA 77A50B50 5 Bytes JMP 73E9EF30 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] GDI32.dll!CreateScalableFontResourceW 77A5E817 5 Bytes JMP 73E9ECF0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] GDI32.dll!RemoveFontResourceExW 77A5EC5C 5 Bytes JMP 73E9EB90 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] GDI32.dll!GetFontResourceInfoW 77A5EE2D 5 Bytes JMP 73E9EC10 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] WS2_32.dll!WSASocketW 779F3CD3 5 Bytes JMP 0131275B C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] WS2_32.dll!bind 779F4582 5 Bytes JMP 013126AD C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] WS2_32.dll!gethostname 779FA05B 5 Bytes JMP 013126C1 C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] WS2_32.dll!listen 779FB001 5 Bytes JMP 013126B7 C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] WS2_32.dll!gethostbyname 77A07673 5 Bytes JMP 013126F5 C:\Program Files\Sandboxie\SandboxieRpcSs.exe .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ole32.dll!CoMarshalInterface 7644EF03 5 Bytes JMP 73E8A800 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ole32.dll!CoUnmarshalInterface 7644F150 5 Bytes JMP 73E8C4E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ole32.dll!CoGetClassObject 764554AD 5 Bytes JMP 73E8C0F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ole32.dll!CoCreateInstance 76469D0B 5 Bytes JMP 73E8C270 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ole32.dll!CoCreateInstanceEx 76469D4E 5 Bytes JMP 73E8C370 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[2400] ole32.dll!CoGetObject Teil1 |
.text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtAlpcConnectPort 77895348 5 Bytes JMP 73EA7770 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtAlpcCreatePort 77895358 5 Bytes JMP 73EA75F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtAlpcImpersonateClientOfPort 778953F8 5 Bytes JMP 73EA6040 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtAlpcQueryInformation 77895428 5 Bytes JMP 73EA5D80 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtAlpcQueryInformationMessage 77895438 5 Bytes JMP 73EA5DB0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtAlpcSendWaitReceivePort 77895458 5 Bytes JMP 73EA66C0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtClose 77895508 5 Bytes JMP 73E9C690 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtConnectPort 77895598 5 Bytes JMP 73EA71B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtCreateEvent 778955E8 5 Bytes JMP 73EA7C50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtCreateFile 77895608 5 Bytes JMP 73E9CF20 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtCreateKey 77895648 5 Bytes JMP 73EAC3E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtCreateMailslotFile 77895678 5 Bytes JMP 73E99EE0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtCreateMutant 77895688 5 Bytes JMP 73EA7FF0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtCreateNamedPipeFile 77895698 5 Bytes JMP 73E9A080 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtCreatePort 778956B8 5 Bytes JMP 73EA7040 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtCreateSection 77895728 5 Bytes JMP 73EA8700 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtCreateSemaphore 77895738 5 Bytes JMP 73EA8360 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtDeleteFile 77895848 5 Bytes JMP 73E95B50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtDeleteKey 77895858 5 Bytes JMP 73EAD000 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtDeleteValueKey 77895888 5 Bytes JMP 73EADD80 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtDeviceIoControlFile 77895898 5 Bytes JMP 73E9A280 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtEnumerateKey 77895928 5 Bytes JMP 73EAD3B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtEnumerateValueKey 77895958 5 Bytes JMP 73EAD9C0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtFsControlFile 77895A48 5 Bytes JMP 73E9C530 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtImpersonateClientOfPort 77895B08 5 Bytes JMP 73EA6010 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtLoadDriver 77895B98 5 Bytes JMP 73EAF650 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtLoadKey 77895BA8 5 Bytes JMP 73EAB610 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtMapViewOfSection 77895C68 5 Bytes JMP 73EAF8C0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtNotifyChangeKey 77895CA8 5 Bytes JMP 73EAC070 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtNotifyChangeMultipleKeys 77895CB8 5 Bytes JMP 73EAB250 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtOpenEvent 77895CF8 5 Bytes JMP 73EA7E40 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtOpenFile 77895D18 5 Bytes JMP 73E9E520 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtOpenKey 77895D48 5 Bytes JMP 73EACF80 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtOpenKeyEx 77895D58 5 Bytes JMP 73EACFB0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtOpenMutant 77895D98 5 Bytes JMP 73EA81B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtOpenSection 77895E08 5 Bytes JMP 73EA8930 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtOpenSemaphore 77895E18 5 Bytes JMP 73EA8550 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtQueryAttributesFile 77895F78 5 Bytes JMP 73E95940 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtQueryDirectoryFile 77895FD8 5 Bytes JMP 73E9A410 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtQueryFullAttributesFile 77896028 5 Bytes JMP 73E99450 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtQueryInformationFile 77896058 5 Bytes JMP 73E9DEA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtQueryKey 77896128 5 Bytes JMP 73EAD020 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtQueryMultipleValueKey 77896148 5 Bytes JMP 73EADB50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtQueryValueKey 77896288 5 Bytes JMP 73EAD780 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtQueryVolumeInformationFile 778962A8 5 Bytes JMP 73E9C870 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtReadFile 778962F8 5 Bytes JMP 73E93220 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtRenameKey 77896408 5 Bytes JMP 73EAB5E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtRequestWaitReplyPort 77896498 5 Bytes JMP 73EA64E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtSaveKey 77896538 5 Bytes JMP 73E8F690 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtSecureConnectPort 77896568 5 Bytes JMP 73EA73B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtSetInformationFile 77896678 5 Bytes JMP 73E9E2A0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtSetValueKey 77896848 5 Bytes JMP 73EABF30 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!NtWriteFile 77896AA8 5 Bytes JMP 73E932F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!LdrUnloadDll 778AC8DE 3 Bytes JMP 73EAF400 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!LdrUnloadDll + 4 778AC8E2 1 Byte [FC] .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!LdrLoadDll 778B22AE 5 Bytes JMP 66DFF140 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!RtlGetFullPathName_UEx 778B5D4E 5 Bytes JMP 73E9B020 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!RtlSetCurrentDirectory_U 778C4ECD 5 Bytes JMP 73E9ADE0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ntdll.dll!RtlGetCurrentDirectory_U 778C4F90 5 Bytes JMP 73E9ABA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] kernel32.dll!MoveFileWithProgressW 77688DD4 5 Bytes JMP 73E93F80 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] kernel32.dll!K32GetDeviceDriverBaseNameW + 5D 7768941E 7 Bytes JMP 6741FDD2 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] kernel32.dll!QueryPerformanceCounter + 13 7768C435 7 Bytes JMP 6741FDF5 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] kernel32.dll!LoadAppInitDlls + 355 7768F4F6 7 Bytes JMP 66E02942 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] kernel32.dll!ReplaceFile 776A1708 5 Bytes JMP 73E9E490 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!RegisterClassExA 76586293 5 Bytes JMP 73EA0CA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!RegisterDeviceNotificationA 76586C53 5 Bytes JMP 73E9F800 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!GetWindowTextA 76586EED 5 Bytes JMP 73EA1AA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!FindWindowExA 76586F69 5 Bytes JMP 73EA1FF0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!GetClassInfoExA 76586FD9 5 Bytes JMP 73EA1040 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!GetClassInfoA 76587158 5 Bytes JMP 73EA1120 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SetParent 76588314 5 Bytes JMP 73E9F620 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SetWindowLongA 76588BA3 5 Bytes JMP 73EA2940 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!MoveWindow 76588D29 5 Bytes JMP 73E9F660 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!UnregisterClassA 76588D70 5 Bytes JMP 73EA0F70 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!FindWindowA 76588FF3 5 Bytes JMP 73EA1EC0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!GetWindowLongA 7658A95E 5 Bytes JMP 73EA2750 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SendMessageA 7658AD60 5 Bytes JMP 73EA2ED0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!UnhookWindowsHookEx 7658ADF9 5 Bytes JMP 73EA3620 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!FindWindowW 7658AE0D 5 Bytes JMP 73EA1E30 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!PostMessageA 7658B446 5 Bytes JMP 73EA31F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!EnumDesktopWindows 7658B4C7 5 Bytes JMP 73EA1D10 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!EnumThreadWindows 7658B712 5 Bytes JMP 73EA1CE0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!GetWindowTextW 7658B8C5 5 Bytes JMP 73EA1A70 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!UnregisterClassW 7658B9AE 2 Bytes JMP 73EA0F10 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!UnregisterClassW + 3 7658B9B1 2 Bytes [91, FD] {XCHG ECX, EAX; STD } .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!DefWindowProcA 7658BB1C 5 Bytes JMP 73E9F560 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!RegisterClassA 7658BC6A 5 Bytes JMP 73EA0E40 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!CreateWindowExA 7658BF40 5 Bytes JMP 73E9F280 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SendNotifyMessageW 7658C88A 5 Bytes JMP 73EA3190 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SetWindowsHookExW 7658E30C 5 Bytes JMP 73EA3940 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SendMessageTimeoutW 7658E459 5 Bytes JMP 73EA3080 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!CreateWindowExW 7658EC7C 5 Bytes JMP 73E9F160 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!RegisterClassW 7658ED4A 5 Bytes JMP 73EA0D70 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!RegisterClassExW 76590162 5 Bytes JMP 73EA0BD0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!GetClassInfoExW 7659095E 5 Bytes JMP 73EA0FD0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!GetClassInfoW 76590AC2 5 Bytes JMP 73EA10B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SetWindowPos 76591BC4 5 Bytes JMP 73E9F6B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!EnumChildWindows 76592948 5 Bytes JMP 73EA1CB0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!GetClassNameW 76592A29 5 Bytes JMP 73EA02F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!DispatchMessageA 76592E32 5 Bytes JMP 73EA2BA0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!GetShellWindow 76592FCB 5 Bytes JMP 73EA2090 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!EnumWindows 7659375B 5 Bytes JMP 73EA1C60 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SetWindowLongW 76594449 5 Bytes JMP 73EA28B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!PostMessageW 7659447B 5 Bytes JMP 73EA3270 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!DefWindowProcW 7659507D 5 Bytes JMP 73E9F4F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SendMessageW 76595539 5 Bytes JMP 73EA2F60 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!GetPropW 76595BBE 5 Bytes JMP 73EA2470 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SetPropW 76595DC5 5 Bytes JMP 73EA2530 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!RemovePropW 76595FE1 5 Bytes JMP 73EA25D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!GetWindowLongW 765961B8 5 Bytes JMP 73EA26D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!DispatchMessageW 7659CC61 5 Bytes JMP 73EA2BF0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!NotifyWinEvent + 5D2 7659D590 4 Bytes [B0, 07, EA, 73] .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!CreateDialogParamA 765A1F42 5 Bytes JMP 73EA4600 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!DialogBoxParamW 765A3B9B 5 Bytes JMP 73EA4640 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SendNotifyMessageA 765A493C 5 Bytes JMP 73EA3130 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!CreateDialogIndirectParamA 765A721D 5 Bytes JMP 73EA4530 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!CreateDialogIndirectParamW 765AEA10 5 Bytes JMP 73EA4500 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!GetClassNameA 765B2445 5 Bytes JMP 73EA03D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!RemovePropA 765B2551 5 Bytes JMP 73EA2610 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SetPropA 765B28E5 5 Bytes JMP 73EA2580 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!GetPropA 765B2B61 5 Bytes JMP 73EA24F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!DialogBoxIndirectParamAorW 765B3B40 5 Bytes JMP 73EA44B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!DialogBoxIndirectParamW 765B3B7F 5 Bytes JMP 73EA4560 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!CreateDialogIndirectParamAorW 765B5327 5 Bytes JMP 73EA4450 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!CreateDialogParamW 765B5630 5 Bytes JMP 73EA45C0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SetWindowsHookExA 765B6D0C 5 Bytes JMP 73EA38F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SendMessageTimeoutA 765B6DA9 5 Bytes JMP 73EA3020 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!FindWindowExW 765B712B 5 Bytes JMP 73EA1F50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SetDoubleClickTime 765CC1CB 5 Bytes JMP 73E9F820 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!SwapMouseButton 765CC1FB 5 Bytes JMP 73E9F820 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!DialogBoxParamA 765CCF42 5 Bytes JMP 73EA4680 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!DialogBoxIndirectParamA 765CD274 5 Bytes JMP 73EA4590 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!EndTask 765CFD66 5 Bytes JMP 73E9F770 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] USER32.dll!ExitWindowsEx 765D06C7 5 Bytes JMP 73E9F5D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] GDI32.dll!GetViewportOrgEx + 26C 77A3884B 7 Bytes JMP 6741FD53 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] GDI32.dll!EnumFontFamiliesExW 77A3CE94 5 Bytes JMP 73E9EF50 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] GDI32.dll!GdiAddFontResourceW 77A3E1F1 5 Bytes JMP 73E9EB00 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] GDI32.dll!EnumFontFamiliesExA 77A50B50 5 Bytes JMP 73E9EF30 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] GDI32.dll!CreateScalableFontResourceW 77A5E817 5 Bytes JMP 73E9ECF0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] GDI32.dll!RemoveFontResourceExW 77A5EC5C 5 Bytes JMP 73E9EB90 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] GDI32.dll!GetFontResourceInfoW 77A5EE2D 5 Bytes JMP 73E9EC10 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!RegConnectRegistryW 75E38F01 5 Bytes JMP 73E89180 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!LookupAccountNameW 75E3E276 5 Bytes JMP 73E890B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!CredWriteA 75E77051 5 Bytes JMP 73E8D780 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!CredWriteW 75E77109 5 Bytes JMP 73E8D140 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!CredReadA 75E771C1 5 Bytes JMP 73E8D840 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!CredReadW 75E772A1 5 Bytes JMP 73E8D1D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!CredEnumerateA 75E77381 5 Bytes JMP 73E8D8A0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!CredEnumerateW 75E77481 5 Bytes JMP 73E8D530 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!CredWriteDomainCredentialsA 75E77581 5 Bytes JMP 73E8D7B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!CredWriteDomainCredentialsW 75E77661 5 Bytes JMP 73E8D2B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!CredReadDomainCredentialsA 75E77741 5 Bytes JMP 73E8D870 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!CredReadDomainCredentialsW 75E77841 5 Bytes JMP 73E8D3A0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!CredDeleteA 75E77941 5 Bytes JMP 73E8D810 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!CredDeleteW 75E779F1 5 Bytes JMP 73E8D4E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!CredRenameA 75E77AA1 5 Bytes JMP 73E8D750 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!GetEffectiveRightsFromAclW 75E817B1 5 Bytes JMP 73E892B0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!RegConnectRegistryA 75E8EF59 5 Bytes JMP 73E89140 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ADVAPI32.dll!EnumServicesStatusA + 3 75E92024 2 Bytes [02, FE] {ADD BH, DH} .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ole32.dll!CoMarshalInterface 7644EF03 5 Bytes JMP 73E8A800 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ole32.dll!CoUnmarshalInterface 7644F150 5 Bytes JMP 73E8C4E0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ole32.dll!CoGetClassObject 764554AD 5 Bytes JMP 73E8C0F0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ole32.dll!CoCreateInstance 76469D0B 5 Bytes JMP 73E8C270 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ole32.dll!CoCreateInstanceEx 76469D4E 5 Bytes JMP 73E8C370 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] ole32.dll!CoGetObject 7647B68D 5 Bytes JMP 73E8C1A0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] IPHLPAPI.DLL!IcmpCloseHandle 73E5821A 5 Bytes JMP 73EA9030 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] IPHLPAPI.DLL!IcmpSendEcho2Ex 73E5843C 5 Bytes JMP 73EA9390 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] IPHLPAPI.DLL!IcmpCreateFile 73E58666 5 Bytes JMP 73EA9140 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] IPHLPAPI.DLL!IcmpSendEcho 73E5870B 5 Bytes JMP 73EA9310 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] IPHLPAPI.DLL!IcmpSendEcho2 73E5873B 5 Bytes JMP 73EA9350 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] IPHLPAPI.DLL!CancelMibChangeNotify2 73E59A27 5 Bytes JMP 73EA9110 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] IPHLPAPI.DLL!NotifyRouteChange2 73E5A191 5 Bytes JMP 73EA90C0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] IPHLPAPI.DLL!Icmp6SendEcho2 73E5AA57 5 Bytes JMP 73EA93D0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] IPHLPAPI.DLL!Icmp6CreateFile 73E5ACBD 5 Bytes JMP 73EA9150 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] CRYPT32.dll!CertGetCertificateChain 75A23822 5 Bytes JMP 73E8DF90 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] CRYPT32.dll!CryptProtectData 75A47223 5 Bytes JMP 73E8DDE0 C:\Program Files\Sandboxie\SbieDll.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3280] CRYPT32.dll!CryptUnprotectData 75A47EDF 5 Bytes JMP 73E8DC00 C:\Program Files\Sandboxie\SbieDll.dll ---- Processes - GMER 2.1 ---- Library C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe (*** hidden *** ) @ C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe [2784] 0x00400000 Library C:\Program Files\Enigma Software Group\SpyHunter\ExecutionGuard.dll (*** hidden *** ) @ C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe [2784] 0x10000000 Library C:\Program Files\Enigma Software Group\SpyHunter\ShScanner.dll (*** hidden *** ) @ C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe [2784] 0x68030000 Library C:\Program Files\Enigma Software Group\SpyHunter\Defman.dll (*** hidden *** ) @ C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe [2784] 0x68660000 Library C:\Program Files\Enigma Software Group\SpyHunter\Common.dll (*** hidden *** ) @ C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe [2784] 0x00330000 ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 sector 0: rootkit-like behavior ---- EOF - GMER 2.1 ---- Bekomme jetzt ständig eine mitteilung das meine DNS Einstellungen modifiziert wurden . und es wird gefragt ob ich die Veränderungen aktzeptiere. Oder die Orginaleinstellungen haben möchte ; was möchte ich ?? Sorry für die Mühe, und ein Danke im Vorfeld lieben Gruß Marion |
Zitat:
Lade dir bitte Emsisoft MBR Master herunter und speichere es auf den Desktop.
|
Detected Windows version: 6.1 Build 7601 Service Pack 1 Installing direct disk access driver ... Driver connection handle: 0x000000E0 1 valid drive(s) found. Details for Disk 0 - SAMSUNG HM320II Rev 2AC1: Device name : \\.\PhysicalDrive0 Geometry (C/H/S) : 38913/255/63 Boot loader reputation : Known Good (Windows 7) Cross view comparison : Passed Partition table integrity: Passed Boot loader hashes SHA-1 : 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79 MD5 : A36C5E4F47E84449FF07ED3517B43A31 shoot und emsi zip habe ich per mail geschickt |
Per Mail..? Ich wüsste nicht, wie das geht.. ;) Die beiden Sachen bitte hier anhängen: http://www.trojaner-board.de/attachm...ten-anhang.png |
Liste der Anhänge anzeigen (Anzahl: 1) jetzt bitte ich aber um:applaus: hoffe ich find das beim nächsten mal wieder *g |
:applaus::applaus::applaus: Und kannst du mir sagen, von welchem Programm diese Warnung wegen der DNS-Einstellungen kommt? Ich erkenn das Symbol nicht. |
Das kommt immer noch von meinem Spyhunter 4 Den habe ich aber deinstalliert auf deinen Rat hin. |
Ah, dann hat der sich nicht vollständig deinstalliert. Da helfen wir nach. Schritt 1 SpyHunter entfernen Die folgende Datei hilft dir das Programm restlos zu deinstallieren:
Schritt 2 Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Schritt 3 Starte noch einmal FRST.
Bitte poste in deiner nächsten Antwort:
|
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.5.1 (08.19.2013:1) OS: Windows 7 Home Premium x86 Ran by peppermint on 20.08.2013 at 20:45:13,38 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\apnstub_rasmancs ~~~ Files Successfully deleted: [File] C:\windows\Tasks\rmschedule.job Successfully deleted: [File] "C:\windows\system32\authuitu.dll" Successfully deleted: [File] "C:\windows\system32\turegopt.exe" ~~~ Folders Successfully deleted: [Folder] "C:\Program Files\eusing free registry cleaner" ~~~ FireFox Emptied folder: C:\Users\peppermint\AppData\Roaming\mozilla\firefox\profiles\w5las282.default\minidumps [27 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 20.08.2013 at 20:48:19,27 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 20-08-2013 03 Finde übrigens nichts mehr von Spyhunter , die Meldung kommt auch nicht mehr danke ;-) |
Ok, dann noch eine letzte Kontrolle: ESET Online Scanner
|
Ne kurze Frage während Eset scannt; Soll ich diese ganzen Teile wie JRT,FRST GMER usw. aufheben oder kann ich die sammt logfiles löschen ?? ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=168dd98ab193e64abb7a7bc51e7b3b16 # engine=14842 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-08-20 08:05:43 # local_time=2013-08-20 10:05:43 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 97 21256 122799627 14027 0 # compatibility_mode=5893 16776574 100 82 2601612 128660334 0 0 # scanned=93229 # found=0 # cleaned=0 # scan_time=3349 |
Alle Zeitangaben in WEZ +1. Es ist jetzt 23:41 Uhr. |
Copyright ©2000-2025, Trojaner-Board