burger-inf | 19.07.2012 10:30 | Hi
Hab nochmal gescannt weil irgendetwas ja nicht stimmt bei den vorherigen Logs.
Malwarebyte's: Code:
Malwarebytes Anti-Malware (Test) 1.61.0.1400
www.malwarebytes.org
Datenbank Version: v2012.04.04.08
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Bruno Bucher :: DESKTOP [Administrator]
Schutz: Aktiviert
19.07.2012 08:19:37
mbam-log-2012-07-19 (08-19-37).txt
Art des Suchlaufs: Vollständiger Suchlauf
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 340744
Laufzeit: 56 Minute(n), 27 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)
(Ende) GMER Logfile: Code:
GMER 1.0.15.15641 - hxxp://www.gmer.net
Rootkit scan 2012-07-18 15:29:46
Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3160815AS rev.4.ADA
Running: q803md3v.exe; Driver: C:\Users\BRUNOB~1\AppData\Local\Temp\fxldapoc.sys
---- System - GMER 1.0.15 ----
SSDT 8BB92506 ZwCreateSection
SSDT 8BB92510 ZwRequestWaitReplyPort
SSDT 8BB9250B ZwSetContextThread
SSDT 8BB92515 ZwSetSecurityObject
SSDT 8BB9251A ZwSystemDebugControl
SSDT 8BB924A7 ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 215 850C98D8 4 Bytes [06, 25, B9, 8B]
.text ntkrnlpa.exe!KeSetEvent + 539 850C9BFC 4 Bytes [10, 25, B9, 8B]
.text ntkrnlpa.exe!KeSetEvent + 56D 850C9C30 4 Bytes [0B, 25, B9, 8B]
.text ntkrnlpa.exe!KeSetEvent + 5D1 850C9C94 4 Bytes [15, 25, B9, 8B]
.text ntkrnlpa.exe!KeSetEvent + 619 850C9CDC 4 Bytes [1A, 25, B9, 8B]
.text ...
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8EE0F000, 0x1F8A4C, 0xE8000020]
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\Explorer.EXE[1616] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[1616] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text C:\Windows\Explorer.EXE[1616] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[1616] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text C:\Windows\Explorer.EXE[1616] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[1616] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text C:\Windows\Explorer.EXE[1616] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[1616] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text C:\Windows\Explorer.EXE[1616] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[1616] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text C:\Windows\Explorer.EXE[1616] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[1616] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text C:\Windows\Explorer.EXE[1616] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Windows\Explorer.EXE[1616] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text C:\Windows\Explorer.EXE[1616] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Windows\Explorer.EXE[1616] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text C:\Windows\Explorer.EXE[1616] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text C:\Windows\Explorer.EXE[1616] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text C:\Windows\Explorer.EXE[1616] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text C:\Windows\Explorer.EXE[1616] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text C:\Windows\Explorer.EXE[1616] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[1616] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text C:\Windows\Explorer.EXE[1616] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text C:\Windows\Explorer.EXE[1616] WS2_32.dll!GetAddrInfoW 75EC3D12 6 Bytes JMP 716C000A
.text C:\Windows\Explorer.EXE[1616] WS2_32.dll!connect 75EC40D9 6 Bytes JMP 7175000A
.text C:\Windows\Explorer.EXE[1616] WS2_32.dll!listen 75EC8CD7 6 Bytes JMP 7172000A
.text C:\Windows\Explorer.EXE[1616] WS2_32.dll!gethostbyname 75ED62D4 6 Bytes JMP 716F000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] KERNEL32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[1684] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Windows\System32\mobsync.exe[2024] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\mobsync.exe[2024] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text C:\Windows\System32\mobsync.exe[2024] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\mobsync.exe[2024] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text C:\Windows\System32\mobsync.exe[2024] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\mobsync.exe[2024] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text C:\Windows\System32\mobsync.exe[2024] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\mobsync.exe[2024] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text C:\Windows\System32\mobsync.exe[2024] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\mobsync.exe[2024] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text C:\Windows\System32\mobsync.exe[2024] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\mobsync.exe[2024] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text C:\Windows\System32\mobsync.exe[2024] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Windows\System32\mobsync.exe[2024] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text C:\Windows\System32\mobsync.exe[2024] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Windows\System32\mobsync.exe[2024] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text C:\Windows\System32\mobsync.exe[2024] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text C:\Windows\System32\mobsync.exe[2024] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text C:\Windows\System32\mobsync.exe[2024] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text C:\Windows\System32\mobsync.exe[2024] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text C:\Windows\System32\mobsync.exe[2024] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\mobsync.exe[2024] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text C:\Windows\System32\mobsync.exe[2024] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text F:\Burger-inf\Suisa-Virus_Tools\q803md3v.exe[2068] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Windows\system32\taskeng.exe[2356] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2356] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text C:\Windows\system32\taskeng.exe[2356] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2356] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text C:\Windows\system32\taskeng.exe[2356] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2356] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text C:\Windows\system32\taskeng.exe[2356] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2356] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text C:\Windows\system32\taskeng.exe[2356] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2356] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text C:\Windows\system32\taskeng.exe[2356] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2356] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text C:\Windows\system32\taskeng.exe[2356] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Windows\system32\taskeng.exe[2356] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text C:\Windows\system32\taskeng.exe[2356] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Windows\system32\taskeng.exe[2356] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text C:\Windows\system32\taskeng.exe[2356] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text C:\Windows\system32\taskeng.exe[2356] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text C:\Windows\system32\taskeng.exe[2356] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text C:\Windows\system32\taskeng.exe[2356] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text C:\Windows\system32\taskeng.exe[2356] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2356] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text C:\Windows\system32\taskeng.exe[2356] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text C:\Windows\system32\taskeng.exe[2356] WS2_32.dll!GetAddrInfoW 75EC3D12 6 Bytes JMP 7175000A
.text C:\Windows\system32\taskeng.exe[2356] WS2_32.dll!connect 75EC40D9 6 Bytes JMP 717E000A
.text C:\Windows\system32\taskeng.exe[2356] WS2_32.dll!listen 75EC8CD7 6 Bytes JMP 717B000A
.text C:\Windows\system32\taskeng.exe[2356] WS2_32.dll!gethostbyname 75ED62D4 6 Bytes JMP 7178000A
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE[2644] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] WS2_32.dll!GetAddrInfoW 75EC3D12 6 Bytes JMP 7175000A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] WS2_32.dll!connect 75EC40D9 6 Bytes JMP 717E000A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] WS2_32.dll!listen 75EC8CD7 6 Bytes JMP 717B000A
.text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[2676] WS2_32.dll!gethostbyname 75ED62D4 6 Bytes JMP 7178000A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] WS2_32.dll!GetAddrInfoW 75EC3D12 6 Bytes JMP 7175000A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] WS2_32.dll!connect 75EC40D9 6 Bytes JMP 717E000A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] WS2_32.dll!listen 75EC8CD7 6 Bytes JMP 717B000A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[3048] WS2_32.dll!gethostbyname 75ED62D4 6 Bytes JMP 7178000A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [80, 71]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [86, 71]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [83, 71]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [7A, 71] {JP 0x73}
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [89, 71]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 718D000A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7190000A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 7196000A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 719C000A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7193000A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 7199000A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71A5000A
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] USER32.dll!SendInput + 4 76172F79 2 Bytes [9E, 71]
.text C:\Program Files\Analog Devices\Core\smax4pnp.exe[3276] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A2000A
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [7A, 71] {JP 0x73}
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [80, 71]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [83, 71]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7187000A
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 718A000A
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 7190000A
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 7196000A
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 718D000A
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 7193000A
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] USER32.dll!mouse_event 7617044E 6 Bytes JMP 719F000A
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] USER32.dll!SendInput + 4 76172F79 2 Bytes [98, 71]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] USER32.dll!keybd_event 7619D972 6 Bytes JMP 719C000A
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] WS2_32.dll!GetAddrInfoW 75EC3D12 6 Bytes JMP 71A2000A
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] WS2_32.dll!connect 75EC40D9 6 Bytes JMP 71AB000A
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] WS2_32.dll!listen 75EC8CD7 6 Bytes JMP 71A8000A
.text C:\Program Files\Windows Sidebar\sidebar.exe[3304] WS2_32.dll!gethostbyname 75ED62D4 6 Bytes JMP 71A5000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] KERNEL32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3312] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text C:\Program Files\HP\HP Software Update\hpwuschd2.exe[3376] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Windows\system32\Dwm.exe[3416] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3416] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text C:\Windows\system32\Dwm.exe[3416] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3416] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text C:\Windows\system32\Dwm.exe[3416] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3416] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text C:\Windows\system32\Dwm.exe[3416] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3416] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text C:\Windows\system32\Dwm.exe[3416] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3416] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text C:\Windows\system32\Dwm.exe[3416] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3416] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text C:\Windows\system32\Dwm.exe[3416] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Windows\system32\Dwm.exe[3416] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text C:\Windows\system32\Dwm.exe[3416] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Windows\system32\Dwm.exe[3416] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text C:\Windows\system32\Dwm.exe[3416] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text C:\Windows\system32\Dwm.exe[3416] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text C:\Windows\system32\Dwm.exe[3416] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text C:\Windows\system32\Dwm.exe[3416] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text C:\Windows\system32\Dwm.exe[3416] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[3416] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text C:\Windows\system32\Dwm.exe[3416] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text C:\Windows\system32\Dwm.exe[3416] WS2_32.dll!GetAddrInfoW 75EC3D12 6 Bytes JMP 7175000A
.text C:\Windows\system32\Dwm.exe[3416] WS2_32.dll!connect 75EC40D9 6 Bytes JMP 717E000A
.text C:\Windows\system32\Dwm.exe[3416] WS2_32.dll!listen 75EC8CD7 6 Bytes JMP 717B000A
.text C:\Windows\system32\Dwm.exe[3416] WS2_32.dll!gethostbyname 75ED62D4 6 Bytes JMP 7178000A
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe[3584] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text C:\Program Files\Windows Defender\MSASCui.exe[3612] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe[3816] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] ntdll.dll!NtCreateFile 77684244 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] ntdll.dll!NtCreateFile + 4 77684248 2 Bytes [86, 71]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] ntdll.dll!NtDeleteValueKey 77684664 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] ntdll.dll!NtDeleteValueKey + 4 77684668 2 Bytes [8C, 71]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] ntdll.dll!NtOpenFile 77684A24 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] ntdll.dll!NtOpenFile + 4 77684A28 2 Bytes [83, 71]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] ntdll.dll!NtOpenProcess 77684AA4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] ntdll.dll!NtOpenProcess + 4 77684AA8 2 Bytes [89, 71]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] ntdll.dll!NtSetContextThread 77685094 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] ntdll.dll!NtSetContextThread + 4 77685098 2 Bytes [80, 71]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] ntdll.dll!NtSetValueKey 776852C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] ntdll.dll!NtSetValueKey + 4 776852C8 2 Bytes [8F, 71]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] kernel32.dll!LoadLibraryExW + 173 763C93EF 4 Bytes JMP 71AF000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] ADVAPI32.dll!CreateServiceW 765E9EB4 6 Bytes JMP 7193000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] ADVAPI32.dll!CreateServiceA 766272A1 6 Bytes JMP 7196000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] USER32.dll!PostMessageA 7614F8F8 6 Bytes JMP 719C000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] USER32.dll!SendMessageA 7614F956 6 Bytes JMP 71A2000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] USER32.dll!PostMessageW 7615A175 6 Bytes JMP 7199000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] USER32.dll!SendMessageW 76160AED 6 Bytes JMP 719F000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] USER32.dll!mouse_event 7617044E 6 Bytes JMP 71AB000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] USER32.dll!SendInput 76172F75 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] USER32.dll!SendInput + 4 76172F79 2 Bytes [A4, 71]
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] USER32.dll!keybd_event 7619D972 6 Bytes JMP 71A8000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] WS2_32.dll!GetAddrInfoW 75EC3D12 6 Bytes JMP 7175000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] WS2_32.dll!connect 75EC40D9 6 Bytes JMP 717E000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] WS2_32.dll!listen 75EC8CD7 6 Bytes JMP 717B000A
.text C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe[4016] WS2_32.dll!gethostbyname 75ED62D4 6 Bytes JMP 7178000A
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ---- AutoRuns (im Anhang ist die *.arn datei, die ist übersichtlicher und auch die Anwendung (autoruns.exe) ist dabei)
AutoRuns zeigt alle Anwendungen auf, die beim Systemstart ausgeführt werden oder es probieren: Code:
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" "" "" ""
+ "Adobe ARM" "Adobe Reader and Acrobat Manager" "Adobe Systems Incorporated" "c:\program files\common files\adobe\arm\1.0\adobearm.exe"
+ "avgnt" "Avira System Tray Tool" "Avira Operations GmbH & Co. KG" "c:\program files\avira\antivir desktop\avgnt.exe"
+ "ContentTransferWMDetector.exe" "Content Transfer Walkman Detector" "Sony Corporation" "c:\program files\sony\content transfer\contenttransferwmdetector.exe"
+ "emsisoft anti-malware" "Background Guard" "Emsisoft GmbH" "c:\program files\emsisoft anti-malware\a2guard.exe"
+ "HP Software Update" "hpwuSchd Application" "Hewlett-Packard" "c:\program files\hp\hp software update\hpwuschd2.exe"
+ "Malwarebytes' Anti-Malware" "Malwarebytes Anti-Malware" "Malwarebytes Corporation" "c:\program files\malwarebytes' anti-malware\mbamgui.exe"
+ "PDVDDXSrv" "CyberLink PowerDVD Resident Program" "CyberLink Corp." "c:\program files\cyberlink\powerdvd dx\pdvddxsrv.exe"
+ "SoundMAXPnP" "SMax4PNP" "Analog Devices, Inc." "c:\program files\analog devices\core\smax4pnp.exe"
+ "StartCCC" "Catalyst® Control Center Launcher" "Advanced Micro Devices, Inc." "c:\program files\ati technologies\ati.ace\core-static\clistart.exe"
+ "Windows Defender" "Windows Defender User Interface" "Microsoft Corporation" "c:\program files\windows defender\msascui.exe"
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" "" "" ""
+ "Malwarebytes Anti-Malware" "Malwarebytes Anti-Malware" "Malwarebytes Corporation" "c:\program files\malwarebytes' anti-malware\mbamgui.exe"
"C:\Users\Bruno Bucher\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup" "" "" ""
+ "OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk" "Microsoft Office OneNote Quick Launcher" "Microsoft Corporation" "c:\program files\microsoft office\office12\onenotem.exe"
"HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components" "" "" ""
+ "Microsoft Windows Mail 7" "Windows Mail" "Microsoft Corporation" "c:\program files\windows mail\winmail.exe"
"HKCU\Software\Microsoft\Windows\CurrentVersion\Run" "" "" ""
+ "Sidebar" "Windows-Sidebar" "Microsoft Corporation" "c:\program files\windows sidebar\sidebar.exe"
+ "swg" "GoogleToolbarNotifier" "Google Inc." "c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe"
+ "WMPNSCFG" "Windows Media Player Network Sharing Service Configuration Application" "Microsoft Corporation" "c:\program files\windows media player\wmpnscfg.exe"
"HKLM\SOFTWARE\Classes\Protocols\Filter" "" "" ""
+ "text/xml" "Microsoft Office XML MIME Filter" "Microsoft Corporation" "c:\program files\common files\microsoft shared\office12\msoxmlmf.dll"
"HKLM\SOFTWARE\Classes\Protocols\Handler" "" "" ""
+ "livecall" "Windows Live Messenger Protocol Handler Module" "Microsoft Corporation" "c:\program files\windows live\messenger\msgrapp.14.0.8050.1202.dll"
+ "ms-help" "Microsoft® Help Data Services Module" "Microsoft Corporation" "c:\program files\common files\microsoft shared\help\hxds.dll"
+ "msnim" "Windows Live Messenger Protocol Handler Module" "Microsoft Corporation" "c:\program files\windows live\messenger\msgrapp.14.0.8050.1202.dll"
+ "wlmailhtml" "Windows Live Mail" "Microsoft Corporation" "c:\program files\windows live\mail\mailcomm.dll"
"HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers" "" "" ""
+ "Shell Extension for Malware scanning" "Avira Shell Extension Library" "Avira Operations GmbH & Co. KG" "c:\program files\avira\antivir desktop\shlext.dll"
"HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers" "" "" ""
+ "a-squared Anti-Malware Shell Extension" "Emsisoft Anti-Malware shell extension" "Emsiûoft GmbH" "c:\program files\emsisoft anti-malware\a2contmenu.dll"
+ "MBAMShlExt" "Malwarebytes Anti-Malware" "Malwarebytes Corporation" "c:\program files\malwarebytes' anti-malware\mbamext.dll"
"HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers" "" "" ""
+ "ACE" "ACE Context Menu" "" "c:\program files\ati technologies\ati.ace\core-static\atiacmxx.dll"
"HKLM\Software\Classes\Folder\Shellex\ColumnHandlers" "" "" ""
+ "PDF Shell Extension" "PDF Shell Extension" "Adobe Systems, Inc." "c:\program files\common files\adobe\acrobat\activex\pdfshell.dll"
"HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers" "" "" ""
+ "a-squared Anti-Malware Shell Extension" "Emsisoft Anti-Malware shell extension" "Emsiûoft GmbH" "c:\program files\emsisoft anti-malware\a2contmenu.dll"
+ "MBAMShlExt" "Malwarebytes Anti-Malware" "Malwarebytes Corporation" "c:\program files\malwarebytes' anti-malware\mbamext.dll"
+ "Shell Extension for Malware scanning" "Avira Shell Extension Library" "Avira Operations GmbH & Co. KG" "c:\program files\avira\antivir desktop\shlext.dll"
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects" "" "" ""
+ "Adobe PDF Link Helper" "Adobe PDF Helper for Internet Explorer" "Adobe Systems Incorporated" "c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll"
+ "Bing Bar Helper" "Bing Client Extensions" "Microsoft Corporation." "c:\program files\microsoft\bingbar\7.1.361.0\bingext.dll"
+ "Google Toolbar Helper" "Google Toolbar" "Google Inc." "c:\program files\google\google toolbar\googletoolbar_32.dll"
+ "Java(tm) Plug-In 2 SSV Helper" "Java(TM) Platform SE binary" "Sun Microsystems, Inc." "c:\program files\java\jre6\bin\jp2ssv.dll"
+ "Java(tm) Plug-In SSV Helper" "Java(TM) Platform SE binary" "Sun Microsystems, Inc." "c:\program files\java\jre6\bin\ssv.dll"
+ "Windows Live Anmelde-Hilfsprogramm" "WindowsLiveLogin.dll" "Microsoft Corporation" "c:\program files\common files\microsoft shared\windows live\windowslivelogin.dll"
"HKLM\Software\Microsoft\Internet Explorer\Toolbar" "" "" ""
+ "Bing" "Bing Client Extensions" "Microsoft Corporation." "c:\program files\microsoft\bingbar\7.1.361.0\bingext.dll"
+ "Google Toolbar" "Google Toolbar" "Google Inc." "c:\program files\google\google toolbar\googletoolbar_32.dll"
"Task Scheduler" "" "" ""
+ "\HPCustParticipation HP Officejet 6600" "HP Customer Participation." "Hewlett-Packard Co." "c:\program files\hp\hp officejet 6600\bin\hpcustpartic.exe"
+ "\hpUrlLauncher.exe_{FB3D7A94-3954-4B4F-A92D-95043B0E0AAB}" "hpUrlLauncher" "Hewlett-Packard Co." "c:\program files\hp\hp officejet 6600\bin\utils\hpurllauncher.exe"
+ "\Microsoft\Windows Defender\MP Scheduled Scan" "Windows Defender Command Line Utility" "Microsoft Corporation" "c:\program files\windows defender\mpcmdrun.exe"
+ "\Microsoft\Windows\Wired\GatherWiredInfo" "" "" "c:\windows\system32\gatherwiredinfo.vbs"
+ "\Microsoft\Windows\Wireless\GatherWirelessInfo" "" "" "c:\windows\system32\gatherwirelessinfo.vbs"
"HKLM\System\CurrentControlSet\Services" "" "" ""
+ "a2AntiMalware" "Scans the PC for unwanted software and provides protection from malicious code" "Emsisoft GmbH" "c:\program files\emsisoft anti-malware\a2service.exe"
+ "AdobeARMservice" "Adobe Acrobat Updater hält Ihre Adobe-Software aktuell." "Adobe Systems Incorporated" "c:\program files\common files\adobe\arm\1.0\armsvc.exe"
+ "AntiVirSchedulerService" "Dienst zur Steuerung von Avira Free Antivirus Prüfaufträgen und Updates." "Avira Operations GmbH & Co. KG" "c:\program files\avira\antivir desktop\sched.exe"
+ "AntiVirService" "Bietet permanenten Schutz vor Viren und Malware mit der Avira Suchengine." "Avira Operations GmbH & Co. KG" "c:\program files\avira\antivir desktop\avguard.exe"
+ "Ati External Event Utility" "ATI External Event Utility EXE Module" "ATI Technologies Inc." "c:\windows\system32\ati2evxx.exe"
+ "BBSvc" "Keeps Bing Bar up-to-date. Disabling this service might prevent updates and expose your computer to security vulnerabilities or functional flaws in Bing Bar." "Microsoft Corporation." "c:\program files\microsoft\bingbar\7.1.361.0\bbsvc.exe"
+ "BBUpdate" "Enables the detection, download and installation of up-to-date configuration files for Bing Bar. Also provides server communication for the customer experience improvement program. Stopping or disabling this service may prevent you from getting the latest updates for Bing Bar, which may expose your computer to security vulnerabilities or functional flaws in the Bing Bar." "Microsoft Corporation." "c:\program files\microsoft\bingbar\7.1.361.0\seaport.exe"
+ "gupdate" "Hält Ihre Google-Software auf dem neuesten Stand. Falls dieser Service deaktiviert oder angehalten wird, wird Ihre Google-Software nicht aktualisiert. Das heißt, dass eventuell auftretende Sicherheitslücken nicht behoben und bestimmte Funktionen möglicherweise nicht ausgeführt werden können. Dieser Service deinstalliert sich selbst, wenn er nicht von einer Google-Software verwendet wird." "Google Inc." "c:\program files\google\update\googleupdate.exe"
+ "gupdatem" "Hält Ihre Google-Software auf dem neuesten Stand. Falls dieser Service deaktiviert oder angehalten wird, wird Ihre Google-Software nicht aktualisiert. Das heißt, dass eventuell auftretende Sicherheitslücken nicht behoben und bestimmte Funktionen möglicherweise nicht ausgeführt werden können. Dieser Service deinstalliert sich selbst, wenn er nicht von einer Google-Software verwendet wird." "Google Inc." "c:\program files\google\update\googleupdate.exe"
+ "gusvc" "Google Updater keeps your Google software up to date. If Google Updater Service is disabled or stopped, your Google software will not be kept up to date, meaning security vulnerabilities that may arise cannot be fixed and features may not work." "Google" "c:\program files\google\common\google updater\googleupdaterservice.exe"
+ "MBAMService" "Malwarebytes Anti-Malware service" "Malwarebytes Corporation" "c:\program files\malwarebytes' anti-malware\mbamservice.exe"
+ "odserv" "Komponenten der Microsoft Office-Diagnose ausführen." "Microsoft Corporation" "c:\program files\common files\microsoft shared\office12\odserv.exe"
+ "ose" "Speichert Installationsdateien, die für Updates und Reparieren verwendet werden, und ist zum Herunterladen von Setup-Updates und Watson-Fehlerberichten erforderlich." "Microsoft Corporation" "c:\program files\common files\microsoft shared\source engine\ose.exe"
+ "SCVSSService" "Provides Volume Shadow Copy service backup support for Second Copy." "" "c:\program files\second copy 8\scvsssvc.exe"
+ "stllssvr" "SureThing Labelflash Disc Printer Service Module" "MicroVision Development, Inc." "c:\program files\common files\surething shared\stllssvr.exe"
+ "WinDefend" "Überprüft den Computer auf unerwünschte Software, plant Überprüfungen und lädt die neuesten Softwaredefinitionen herunter." "Microsoft Corporation" "c:\program files\windows defender\mpsvc.dll"
+ "WMPNetworkSvc" "Gibt Windows Media Player-Bibliotheken mithilfe des universellen Plug & Play für andere Players und Mediengeräte auf dem Netzwerk frei" "Microsoft Corporation" "c:\program files\windows media player\wmpnetwk.exe"
"HKLM\System\CurrentControlSet\Services" "" "" ""
+ "a2acc" "Emsisoft on-access minifilter" "" "File not found: C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys"
+ "A2DDA" "Emsisoft Direct Disk Access Support Driver" "Emsi Software GmbH" "c:\program files\emsisoft anti-malware\a2ddax86.sys"
+ "a2util" "Provides several additional functionality used by the a-squared Malware-IDS." "Emsi Software GmbH" "c:\program files\emsisoft anti-malware\a2util32.sys"
+ "ADIHdAudAddService" "High Definition Audio Function Driver" "Analog Devices, Inc." "c:\windows\system32\drivers\adihdaud.sys"
+ "atikmdag" "ATI Radeon Kernel Mode Driver" "ATI Technologies Inc." "c:\windows\system32\drivers\atikmdag.sys"
+ "avgntflt" "Avira mini-filter driver" "Avira GmbH" "c:\windows\system32\drivers\avgntflt.sys"
+ "avipbb" "Avira Security Enhancement Driver" "Avira GmbH" "c:\windows\system32\drivers\avipbb.sys"
+ "avkmgr" "Avira Manager Driver" "Avira GmbH" "c:\windows\system32\drivers\avkmgr.sys"
+ "BrFiltLo" "Windows ME USB Mass-Storage Bulk-Only Lower Filter Driver" "Brother Industries, Ltd." "c:\windows\system32\drivers\brfiltlo.sys"
+ "BrFiltUp" "Windows ME USB Mass-Storage Bulk-Only Upper Filter Driver" "Brother Industries, Ltd." "c:\windows\system32\drivers\brfiltup.sys"
+ "BrUsbSer" "Brother USB Serial Driver" "Brother Industries Ltd." "c:\windows\system32\drivers\brusbser.sys"
+ "e1express" "Intel(R) PRO/1000 Adapter NDIS 6-nicht serialisierter Treiber" "Intel Corporation" "c:\windows\system32\drivers\e1e6032.sys"
+ "E1G60" "Intel(R) PRO/1000 Adapter NDIS 6-nicht serialisierter Treiber" "Intel Corporation" "c:\windows\system32\drivers\e1g60i32.sys"
+ "IpInIp" "IP in IP Tunnel Driver" "" "File not found: system32\DRIVERS\ipinip.sys"
+ "k57nd60x" "Broadcom NetLink (TM) Gigabit Ethernet NDIS6.x Unified Driver." "Broadcom Corporation" "c:\windows\system32\drivers\k57nd60x.sys"
+ "MBAMProtector" "Malwarebytes Anti-Malware" "Malwarebytes Corporation" "c:\windows\system32\drivers\mbam.sys"
+ "NwlnkFlt" "IPX Traffic Filter Driver" "" "File not found: system32\DRIVERS\nwlnkflt.sys"
+ "NwlnkFwd" "IPX Traffic Forwarder Driver" "" "File not found: system32\DRIVERS\nwlnkfwd.sys"
+ "PxHelp20" "Px Engine Device Driver for Windows 2000/XP" "Sonic Solutions" "c:\windows\system32\drivers\pxhelp20.sys"
+ "R300" "ATI Radeon Kernel Mode Driver" "ATI Technologies Inc." "c:\windows\system32\drivers\atikmdag.sys"
+ "secdrv" "Macrovision SECURITY Driver" "Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K." "c:\windows\system32\drivers\secdrv.sys"
+ "ssmdrv" "Avira Snapshot Driver" "Avira GmbH" "c:\windows\system32\drivers\ssmdrv.sys"
+ "VST_DPV" "HSF_DP driver" "Conexant Systems, Inc." "c:\windows\system32\drivers\vstdpv3.sys"
+ "VSTHWBS2" "HSF_HWB2 WDM driver" "Conexant Systems, Inc." "c:\windows\system32\drivers\vstbs23.sys"
+ "winachsf" "HSF_CNXT driver" "Conexant Systems, Inc." "c:\windows\system32\drivers\vstcnxt3.sys"
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32" "" "" ""
+ "msacm.l3acm" "MPEG Layer-3 Audio Codec for MSACM" "Fraunhofer Institut Integrierte Schaltungen IIS" "c:\windows\system32\l3codeca.acm"
+ "vidc.cvid" "Cinepak(C) Codec" "Radius Inc." "c:\windows\system32\iccvid.dll"
"HKLM\Software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance" "" "" ""
+ "9x8Resize" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "Allocator Fix" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "ATI Ticker" "" "" "c:\program files\ati technologies\ati.ace\graphics-previews-common\ticker.ax"
+ "Bitmap" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "Capture ASF Writer" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "Capture File Writer" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files\windows live\photo gallery\wlxvafilt.dll"
+ "CyberLink Audio Decoder" "CyberLink Audio Decoder Filter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd dx\kernel\movie\claud.ax"
+ "CyberLink Audio Effect" "CyberLink Audio Effect Filter" "CyberLink Corporation" "c:\program files\cyberlink\powerdvd dx\kernel\movie\claudfx.ax"
+ "CyberLink Audio Spectrum Analyzer" "CLAudSpa.ax" "CyberLink Corp." "c:\program files\cyberlink\powerdvd dx\kernel\movie\claudspa.ax"
+ "CyberLink Audio Wizard" "CyberLink Audio Wizard Filter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd dx\kernel\movie\claudwizard.ax"
+ "CyberLink AudioCD Filter" "CyberLink AudioCD Filter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd dx\kernel\movie\claudiocd.ax"
+ "CyberLink Demultiplexer" "MPEG-2 Dempltiplexer" "CyberLink Corp." "c:\program files\cyberlink\powerdvd dx\kernel\movie\cldemuxer.ax"
+ "CyberLink DVD Navigator" "CyberLink DVD Navigation Filter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd dx\kernel\movie\clnavx.ax"
+ "CyberLink Line21 Decoder Filter" "CyberLink Line21 Decoder Filter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd dx\kernel\movie\clline21.ax"
+ "Cyberlink SubTitle Importor" "CLSubTitle.ax" "CyberLink Corp." "c:\program files\cyberlink\powerdvd dx\kernel\movie\clsubtitle.ax"
+ "CyberLink TimeStretch Filter" "CLAuTS.ax" "CyberLink Corp." "c:\program files\cyberlink\powerdvd dx\kernel\movie\clauts.ax"
+ "CyberLink Video Effect" "CLVidFx" "CyberLink" "c:\program files\cyberlink\powerdvd dx\kernel\movie\clvidfx.ax"
+ "CyberLink Video/SP Decoder" "CyberLink Video/SP Filter" "CyberLink Corp." "c:\program files\cyberlink\powerdvd dx\kernel\movie\clvsd.ax"
+ "Frame Eater" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "MMACE Deinterlace" "" "" "c:\program files\ati technologies\ati.ace\graphics-previews-common\mmacefilters.dll"
+ "MMACE ProcAmp" "" "" "c:\program files\ati technologies\ati.ace\graphics-previews-common\mmacefilters.dll"
+ "MMACE SoftEmu" "" "" "c:\program files\ati technologies\ati.ace\graphics-previews-common\mmacefilters.dll"
+ "Multiple File Output" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "Proxy Sink" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "Proxy Source" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "Record Queue" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files\windows live\photo gallery\wlxvafilt.dll"
+ "Record Queue" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "ShotDetect" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "Sonic Cinemaster® Audio Decoder 4.2" "SonicHDAudio" "Sonic Solutions" "c:\program files\common files\sonic shared\cinemasteraudio.dll"
+ "Sonic Cinemaster® VideoDecoder 4.1" "CinemasterVideo" "Sonic Solutions" "c:\program files\common files\sonic shared\cinemastervideo.dll"
+ "Sonic HD Demuxer" "Sonic HD Demuxer" "" "c:\program files\common files\sonic shared\sonichddemuxer.dll"
+ "Sonic HD Nav" "SonicHDNav" "" "c:\program files\common files\sonic shared\sonichdnav.dll"
+ "Sony ATRAC3/3plus Decode Filter" "Sony ATRAC3/3plus Decode Filter" "Sony Corporation" "c:\windows\system32\atxdec.ax"
+ "Sony ATRAC3/3plus Parse Filter" "Sony ATRAC3/3plus Parse Filter" "Sony Corporation" "c:\windows\system32\atxparser.ax"
+ "SonyMp4AacDecoder" "SonyMp4AacDecoder" "sony" "c:\program files\sony\content transfer\sonymp4aacdecoder.ax"
+ "Stetch" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "WM VIH2 Fix" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files\windows live\photo gallery\wlxvafilt.dll"
+ "WM VIH2 Fix" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "WMT Audio Analyzer" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "WMT Black Frame Generator" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "WMT DV Extract Filter" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files\windows live\photo gallery\wlxvafilt.dll"
+ "WMT DV Extract Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "WMT FormatConversion" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "WMT Import Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "WMT Interlacer" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "WMT Log Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "WMT MuxDeMux Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "WMT Sample Info Filter" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files\windows live\photo gallery\wlxvafilt.dll"
+ "WMT Sample Info Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "WMT Switch Filter" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files\windows live\photo gallery\wlxvafilt.dll"
+ "WMT Switch Filter" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "WMT Virtual Renderer" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files\windows live\photo gallery\wlxvafilt.dll"
+ "WMT Virtual Renderer" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "WMT Virtual Source" "Windows Live Video Acquisition Filters" "Microsoft Corporation" "c:\program files\windows live\photo gallery\wlxvafilt.dll"
+ "WMT Virtual Source" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
+ "WMT Volume" "Windows Movie Maker Filters" "Microsoft Corporation" "c:\program files\movie maker\wmm2filt.dll"
"HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors" "" "" ""
+ "CNY SELPHY CP LM13" "SELPHY CP Family Driver Language Monitor" "Canon INC." "c:\windows\system32\cnymlm13.dll"
+ "CutePDF Writer Monitor" "" "" "c:\windows\system32\cpwmon2k.dll"
+ "HP 5D12 Status Monitor" "Print Status Language Monitor" "Hewlett-Packard Co." "c:\windows\system32\hpinksts5d12lm.dll"
+ "HP Discovery Port Monitor (HP Officejet 6600)" "HP Discovery Port Monitor" "Hewlett-Packard Co." "c:\windows\system32\hpdiscopm5d12.dll"
"C:\Users\Bruno Bucher\AppData\Local\Microsoft\Windows Sidebar\Settings.ini" "" "" "" |