Code:
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-10-21 11:38:34
Windows 5.1.2600
---- System - GMER 1.0.13 ----
SSDT \??\C:\WINDOWS\System32\xpdx.sys ZwCreateKey
SSDT F9B647AC ZwCreateThread
SSDT \??\C:\WINDOWS\System32\xpdx.sys ZwOpenKey
SSDT F9B64798 ZwOpenProcess
SSDT F9B6479D ZwOpenThread
SSDT F9B647A7 ZwTerminateProcess
SSDT F9B647A2 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.13 ----
.text ntoskrnl.exe!KeInitializeInterrupt + B79 804D4F8E 1 Byte [ 06 ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 1B0 804FC6C8 4 Bytes [ 85, 9A, 74, F9 ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 1E0 804FC6F8 4 Bytes [ AC, 47, B6, F9 ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 2E8 804FC800 4 Bytes [ 39, 9B, 74, F9 ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 2F4 804FC80C 4 Bytes [ 98, 47, B6, F9 ]
.text ntoskrnl.exe!KeI386Call16BitCStyleFunction + 30C 804FC824 4 Bytes [ 9D, 47, B6, F9 ]
.text ...
? C:\WINDOWS\System32\xpdx.sys Das System kann die angegebene Datei nicht finden.
? C:\WINDOWS\System32\Drivers\mchInjDrv.sys Das System kann die angegebene Datei nicht finden.
---- User code sections - GMER 1.0.13 ----
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtClose 77F6E543 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtClose + 4 77F6E547 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtCreateFile 77F6E603 1 Byte [ FF ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtCreateFile + 2 77F6E605 1 Byte [ 1E ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtCreateFile + 4 77F6E607 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtCreateKey 77F6E643 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtCreateKey + 4 77F6E647 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtCreateSection 77F6E6D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtCreateSection + 4 77F6E6D7 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtDeleteKey 77F6E7A3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtDeleteKey + 4 77F6E7A7 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtDeleteValueKey 77F6E7C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtDeleteValueKey + 4 77F6E7C7 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtSetInformationFile 77F6F1B3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtSetInformationFile + 4 77F6F1B7 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtSetValueKey 77F6F323 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtSetValueKey + 4 77F6F327 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtTerminateProcess 77F6F3C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtTerminateProcess + 4 77F6F3C7 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtWriteFile 77F6F4D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtWriteFile + 4 77F6F4D7 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtWriteFileGather 77F6F4E3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtWriteFileGather + 4 77F6F4E7 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtWriteVirtualMemory 77F6F503 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\csrss.exe[492] ntdll.dll!NtWriteVirtualMemory + 4 77F6F507 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\csrss.exe[492] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\system32\csrss.exe[492] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\csrss.exe[492] KERNEL32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtClose 77F6E543 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtClose + 4 77F6E547 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtCreateFile 77F6E603 1 Byte [ FF ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtCreateFile + 2 77F6E605 1 Byte [ 1E ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtCreateFile + 4 77F6E607 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtCreateKey 77F6E643 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtCreateKey + 4 77F6E647 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtCreateSection 77F6E6D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtCreateSection + 4 77F6E6D7 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtDeleteKey 77F6E7A3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtDeleteKey + 4 77F6E7A7 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtDeleteValueKey 77F6E7C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtDeleteValueKey + 4 77F6E7C7 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtSetInformationFile 77F6F1B3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtSetInformationFile + 4 77F6F1B7 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtSetValueKey 77F6F323 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtSetValueKey + 4 77F6F327 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtTerminateProcess 77F6F3C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtTerminateProcess + 4 77F6F3C7 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtWriteFile 77F6F4D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtWriteFile + 4 77F6F4D7 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtWriteFileGather 77F6F4E3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtWriteFileGather + 4 77F6F4E7 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtWriteVirtualMemory 77F6F503 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\winlogon.exe[516] ntdll.dll!NtWriteVirtualMemory + 4 77F6F507 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\winlogon.exe[516] kernel32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\winlogon.exe[516] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\system32\winlogon.exe[516] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtClose 77F6E543 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtClose + 4 77F6E547 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtCreateFile 77F6E603 1 Byte [ FF ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtCreateFile + 2 77F6E605 1 Byte [ 1E ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtCreateFile + 4 77F6E607 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtCreateKey 77F6E643 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtCreateKey + 4 77F6E647 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtCreateSection 77F6E6D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtCreateSection + 4 77F6E6D7 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtDeleteKey 77F6E7A3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtDeleteKey + 4 77F6E7A7 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtDeleteValueKey 77F6E7C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtDeleteValueKey + 4 77F6E7C7 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtSetInformationFile 77F6F1B3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtSetInformationFile + 4 77F6F1B7 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtSetValueKey 77F6F323 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtSetValueKey + 4 77F6F327 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtTerminateProcess 77F6F3C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtTerminateProcess + 4 77F6F3C7 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtWriteFile 77F6F4D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtWriteFile + 4 77F6F4D7 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtWriteFileGather 77F6F4E3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtWriteFileGather + 4 77F6F4E7 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtWriteVirtualMemory 77F6F503 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\services.exe[564] ntdll.dll!NtWriteVirtualMemory + 4 77F6F507 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\services.exe[564] kernel32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\services.exe[564] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\system32\services.exe[564] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtClose 77F6E543 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtClose + 4 77F6E547 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtCreateFile 77F6E603 1 Byte [ FF ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtCreateFile + 2 77F6E605 1 Byte [ 1E ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtCreateFile + 4 77F6E607 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtCreateKey 77F6E643 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtCreateKey + 4 77F6E647 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtCreateSection 77F6E6D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtCreateSection + 4 77F6E6D7 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtDeleteKey 77F6E7A3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtDeleteKey + 4 77F6E7A7 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtDeleteValueKey 77F6E7C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtDeleteValueKey + 4 77F6E7C7 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtSetInformationFile 77F6F1B3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtSetInformationFile + 4 77F6F1B7 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtSetValueKey 77F6F323 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtSetValueKey + 4 77F6F327 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtTerminateProcess 77F6F3C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtTerminateProcess + 4 77F6F3C7 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtWriteFile 77F6F4D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtWriteFile + 4 77F6F4D7 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtWriteFileGather 77F6F4E3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtWriteFileGather + 4 77F6F4E7 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtWriteVirtualMemory 77F6F503 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\lsass.exe[576] ntdll.dll!NtWriteVirtualMemory + 4 77F6F507 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\lsass.exe[576] kernel32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\lsass.exe[576] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\system32\lsass.exe[576] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F2B0F5A
.text C:\Programme\Spyware Doctor\SDTrayApp.exe[620] kernel32.dll!CreateThread + 18 77E5AC4F 4 Bytes [ 65, EC, 5E, 88 ]
.text C:\Programme\Spyware Doctor\SDTrayApp.exe[620] kernel32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text C:\Programme\Spyware Doctor\SDTrayApp.exe[620] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F0A0F5A
.text C:\Programme\Spyware Doctor\SDTrayApp.exe[620] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F040F5A
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtClose 77F6E543 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtClose + 4 77F6E547 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtCreateFile 77F6E603 1 Byte [ FF ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtCreateFile + 2 77F6E605 1 Byte [ 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtCreateFile + 4 77F6E607 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtCreateKey 77F6E643 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtCreateKey + 4 77F6E647 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtCreateSection 77F6E6D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtCreateSection + 4 77F6E6D7 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtDeleteKey 77F6E7A3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtDeleteKey + 4 77F6E7A7 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtDeleteValueKey 77F6E7C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtDeleteValueKey + 4 77F6E7C7 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtSetInformationFile 77F6F1B3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtSetInformationFile + 4 77F6F1B7 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtSetValueKey 77F6F323 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtSetValueKey + 4 77F6F327 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtTerminateProcess 77F6F3C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtTerminateProcess + 4 77F6F3C7 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtWriteFile 77F6F4D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtWriteFile + 4 77F6F4D7 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtWriteFileGather 77F6F4E3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtWriteFileGather + 4 77F6F4E7 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtWriteVirtualMemory 77F6F503 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[804] ntdll.dll!NtWriteVirtualMemory + 4 77F6F507 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\System32\svchost.exe[804] kernel32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\System32\svchost.exe[804] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\System32\svchost.exe[804] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtClose 77F6E543 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtClose + 4 77F6E547 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtCreateFile 77F6E603 1 Byte [ FF ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtCreateFile + 2 77F6E605 1 Byte [ 1E ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtCreateFile + 4 77F6E607 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtCreateKey 77F6E643 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtCreateKey + 4 77F6E647 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtCreateSection 77F6E6D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtCreateSection + 4 77F6E6D7 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtDeleteKey 77F6E7A3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtDeleteKey + 4 77F6E7A7 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtDeleteValueKey 77F6E7C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtDeleteValueKey + 4 77F6E7C7 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtSetInformationFile 77F6F1B3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtSetInformationFile + 4 77F6F1B7 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtSetValueKey 77F6F323 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtSetValueKey + 4 77F6F327 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtTerminateProcess 77F6F3C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtTerminateProcess + 4 77F6F3C7 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtWriteFile 77F6F4D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtWriteFile + 4 77F6F4D7 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtWriteFileGather 77F6F4E3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtWriteFileGather + 4 77F6F4E7 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtWriteVirtualMemory 77F6F503 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\svchost.exe[1060] ntdll.dll!NtWriteVirtualMemory + 4 77F6F507 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\System32\svchost.exe[1060] kernel32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\System32\svchost.exe[1060] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\System32\svchost.exe[1060] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtClose 77F6E543 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtClose + 4 77F6E547 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtCreateFile 77F6E603 1 Byte [ FF ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtCreateFile + 2 77F6E605 1 Byte [ 1E ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtCreateFile + 4 77F6E607 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtCreateKey 77F6E643 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtCreateKey + 4 77F6E647 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtCreateSection 77F6E6D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtCreateSection + 4 77F6E6D7 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtDeleteKey 77F6E7A3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtDeleteKey + 4 77F6E7A7 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtDeleteValueKey 77F6E7C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtDeleteValueKey + 4 77F6E7C7 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtSetInformationFile 77F6F1B3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtSetInformationFile + 4 77F6F1B7 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtSetValueKey 77F6F323 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtSetValueKey + 4 77F6F327 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtTerminateProcess 77F6F3C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtTerminateProcess + 4 77F6F3C7 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtWriteFile 77F6F4D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtWriteFile + 4 77F6F4D7 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtWriteFileGather 77F6F4E3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtWriteFileGather + 4 77F6F4E7 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtWriteVirtualMemory 77F6F503 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\Explorer.EXE[1264] ntdll.dll!NtWriteVirtualMemory + 4 77F6F507 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\Explorer.EXE[1264] kernel32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\Explorer.EXE[1264] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\Explorer.EXE[1264] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtClose 77F6E543 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtClose + 4 77F6E547 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtCreateFile 77F6E603 1 Byte [ FF ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtCreateFile + 2 77F6E605 1 Byte [ 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtCreateFile + 4 77F6E607 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtCreateKey 77F6E643 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtCreateKey + 4 77F6E647 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtCreateSection 77F6E6D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtCreateSection + 4 77F6E6D7 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtDeleteKey 77F6E7A3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtDeleteKey + 4 77F6E7A7 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtDeleteValueKey 77F6E7C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtDeleteValueKey + 4 77F6E7C7 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtSetInformationFile 77F6F1B3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtSetInformationFile + 4 77F6F1B7 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtSetValueKey 77F6F323 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtSetValueKey + 4 77F6F327 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtTerminateProcess 77F6F3C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtTerminateProcess + 4 77F6F3C7 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtWriteFile 77F6F4D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtWriteFile + 4 77F6F4D7 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtWriteFileGather 77F6F4E3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtWriteFileGather + 4 77F6F4E7 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtWriteVirtualMemory 77F6F503 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] ntdll.dll!NtWriteVirtualMemory + 4 77F6F507 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system32\spoolsv.exe[1352] kernel32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system32\spoolsv.exe[1352] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\system32\spoolsv.exe[1352] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtClose 77F6E543 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtClose + 4 77F6E547 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtCreateFile 77F6E603 1 Byte [ FF ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtCreateFile + 2 77F6E605 1 Byte [ 1E ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtCreateFile + 4 77F6E607 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtCreateKey 77F6E643 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtCreateKey + 4 77F6E647 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtCreateSection 77F6E6D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtCreateSection + 4 77F6E6D7 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtDeleteKey 77F6E7A3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtDeleteKey + 4 77F6E7A7 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtDeleteValueKey 77F6E7C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtDeleteValueKey + 4 77F6E7C7 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtSetInformationFile 77F6F1B3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtSetInformationFile + 4 77F6F1B7 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtSetValueKey 77F6F323 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtSetValueKey + 4 77F6F327 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtTerminateProcess 77F6F3C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtTerminateProcess + 4 77F6F3C7 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtWriteFile 77F6F4D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtWriteFile + 4 77F6F4D7 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtWriteFileGather 77F6F4E3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtWriteFileGather + 4 77F6F4E7 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtWriteVirtualMemory 77F6F503 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\logon.exe[1512] ntdll.dll!NtWriteVirtualMemory + 4 77F6F507 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\System32\logon.exe[1512] kernel32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\System32\logon.exe[1512] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\System32\logon.exe[1512] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F2B0F5A
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtClose 77F6E543 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtClose + 4 77F6E547 2 Bytes [ 29, 5F ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtCreateFile 77F6E603 1 Byte [ FF ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtCreateFile + 2 77F6E605 1 Byte [ 1E ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtCreateFile + 4 77F6E607 2 Bytes [ 14, 5F ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtCreateKey 77F6E643 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtCreateKey + 4 77F6E647 2 Bytes [ 05, 5F ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtCreateSection 77F6E6D3 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtCreateSection + 4 77F6E6D7 2 Bytes [ 20, 5F ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtDeleteKey 77F6E7A3 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtDeleteKey + 4 77F6E7A7 2 Bytes [ 0B, 5F ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtDeleteValueKey 77F6E7C3 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtDeleteValueKey + 4 77F6E7C7 2 Bytes [ 11, 5F ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtSetInformationFile 77F6F1B3 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtSetInformationFile + 4 77F6F1B7 2 Bytes [ 1D, 5F ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtSetValueKey 77F6F323 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtSetValueKey + 4 77F6F327 2 Bytes [ 0E, 5F ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtTerminateProcess 77F6F3C3 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtTerminateProcess + 4 77F6F3C7 2 Bytes [ 23, 5F ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtWriteFile 77F6F4D3 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtWriteFile + 4 77F6F4D7 2 Bytes [ 17, 5F ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtWriteFileGather 77F6F4E3 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtWriteFileGather + 4 77F6F4E7 2 Bytes [ 1A, 5F ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtWriteVirtualMemory 77F6F503 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] ntdll.dll!NtWriteVirtualMemory + 4 77F6F507 2 Bytes [ 26, 5F ]
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] kernel32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F2F0F5A
.text C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe[1520] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtClose 77F6E543 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtClose + 4 77F6E547 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtCreateFile 77F6E603 1 Byte [ FF ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtCreateFile + 2 77F6E605 1 Byte [ 1E ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtCreateFile + 4 77F6E607 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtCreateKey 77F6E643 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtCreateKey + 4 77F6E647 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtCreateSection 77F6E6D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtCreateSection + 4 77F6E6D7 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtDeleteKey 77F6E7A3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtDeleteKey + 4 77F6E7A7 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtDeleteValueKey 77F6E7C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtDeleteValueKey + 4 77F6E7C7 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtSetInformationFile 77F6F1B3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtSetInformationFile + 4 77F6F1B7 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtSetValueKey 77F6F323 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtSetValueKey + 4 77F6F327 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtTerminateProcess 77F6F3C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtTerminateProcess + 4 77F6F3C7 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtWriteFile 77F6F4D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtWriteFile + 4 77F6F4D7 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtWriteFileGather 77F6F4E3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtWriteFileGather + 4 77F6F4E7 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtWriteVirtualMemory 77F6F503 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] ntdll.dll!NtWriteVirtualMemory + 4 77F6F507 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\System32\ctfmon.exe[1528] kernel32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\System32\ctfmon.exe[1528] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\System32\ctfmon.exe[1528] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F2B0F5A
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtClose 77F6E543 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtClose + 4 77F6E547 2 Bytes [ 29, 5F ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtCreateFile 77F6E603 1 Byte [ FF ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtCreateFile + 2 77F6E605 1 Byte [ 1E ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtCreateFile + 4 77F6E607 2 Bytes [ 14, 5F ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtCreateKey 77F6E643 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtCreateKey + 4 77F6E647 2 Bytes [ 05, 5F ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtCreateSection 77F6E6D3 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtCreateSection + 4 77F6E6D7 2 Bytes [ 20, 5F ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtDeleteKey 77F6E7A3 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtDeleteKey + 4 77F6E7A7 2 Bytes [ 0B, 5F ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtDeleteValueKey 77F6E7C3 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtDeleteValueKey + 4 77F6E7C7 2 Bytes [ 11, 5F ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtSetInformationFile 77F6F1B3 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtSetInformationFile + 4 77F6F1B7 2 Bytes [ 1D, 5F ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtSetValueKey 77F6F323 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtSetValueKey + 4 77F6F327 2 Bytes [ 0E, 5F ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtTerminateProcess 77F6F3C3 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtTerminateProcess + 4 77F6F3C7 2 Bytes [ 23, 5F ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtWriteFile 77F6F4D3 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtWriteFile + 4 77F6F4D7 2 Bytes [ 17, 5F ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtWriteFileGather 77F6F4E3 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtWriteFileGather + 4 77F6F4E7 2 Bytes [ 1A, 5F ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtWriteVirtualMemory 77F6F503 3 Bytes [ FF, 25, 1E ]
.text C:\Programme\Messenger\msmsgs.exe[1536] ntdll.dll!NtWriteVirtualMemory + 4 77F6F507 2 Bytes [ 26, 5F ]
.text C:\Programme\Messenger\msmsgs.exe[1536] kernel32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text C:\Programme\Messenger\msmsgs.exe[1536] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F2F0F5A
.text C:\Programme\Messenger\msmsgs.exe[1536] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F2B0F5A
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtClose 77F6E543 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtClose + 4 77F6E547 2 Bytes [ 29, 5F ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtCreateFile 77F6E603 1 Byte [ FF ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtCreateFile + 2 77F6E605 1 Byte [ 1E ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtCreateFile + 4 77F6E607 2 Bytes [ 14, 5F ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtCreateKey 77F6E643 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtCreateKey + 4 77F6E647 2 Bytes [ 05, 5F ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtCreateSection 77F6E6D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtCreateSection + 4 77F6E6D7 2 Bytes [ 20, 5F ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtDeleteKey 77F6E7A3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtDeleteKey + 4 77F6E7A7 2 Bytes [ 0B, 5F ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtDeleteValueKey 77F6E7C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtDeleteValueKey + 4 77F6E7C7 2 Bytes [ 11, 5F ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtSetInformationFile 77F6F1B3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtSetInformationFile + 4 77F6F1B7 2 Bytes [ 1D, 5F ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtSetValueKey 77F6F323 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtSetValueKey + 4 77F6F327 2 Bytes [ 0E, 5F ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtTerminateProcess 77F6F3C3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtTerminateProcess + 4 77F6F3C7 2 Bytes [ 23, 5F ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtWriteFile 77F6F4D3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtWriteFile + 4 77F6F4D7 2 Bytes [ 17, 5F ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtWriteFileGather 77F6F4E3 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtWriteFileGather + 4 77F6F4E7 2 Bytes [ 1A, 5F ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtWriteVirtualMemory 77F6F503 3 Bytes [ FF, 25, 1E ]
.text C:\WINDOWS\system\msnrav.exe[1928] ntdll.dll!NtWriteVirtualMemory + 4 77F6F507 2 Bytes [ 26, 5F ]
.text C:\WINDOWS\system\msnrav.exe[1928] kernel32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text C:\WINDOWS\system\msnrav.exe[1928] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F2F0F5A
.text C:\WINDOWS\system\msnrav.exe[1928] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F2B0F5A
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtClose 77F6E543 3 Bytes [ FF, 25, 1E ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtClose + 4 77F6E547 2 Bytes [ 2B, 5F ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtCreateFile 77F6E603 1 Byte [ FF ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtCreateFile + 2 77F6E605 1 Byte [ 1E ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtCreateFile + 4 77F6E607 2 Bytes [ 14, 5F ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtCreateKey 77F6E643 3 Bytes [ FF, 25, 1E ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtCreateKey + 4 77F6E647 2 Bytes [ 05, 5F ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtCreateSection 77F6E6D3 3 Bytes [ FF, 25, 1E ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtCreateSection + 4 77F6E6D7 2 Bytes [ 22, 5F ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtDeleteKey 77F6E7A3 3 Bytes [ FF, 25, 1E ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtDeleteKey + 4 77F6E7A7 2 Bytes [ 0B, 5F ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtDeleteValueKey 77F6E7C3 3 Bytes [ FF, 25, 1E ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtDeleteValueKey + 4 77F6E7C7 2 Bytes [ 11, 5F ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtSetInformationFile 77F6F1B3 3 Bytes [ FF, 25, 1E ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtSetInformationFile + 4 77F6F1B7 2 Bytes [ 1F, 5F ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtSetValueKey 77F6F323 3 Bytes [ FF, 25, 1E ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtSetValueKey + 4 77F6F327 2 Bytes [ 0E, 5F ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtTerminateProcess 77F6F3C3 3 Bytes [ FF, 25, 1E ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtTerminateProcess + 4 77F6F3C7 2 Bytes [ 25, 5F ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtWriteFile 77F6F4D3 3 Bytes [ FF, 25, 1E ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtWriteFile + 4 77F6F4D7 2 Bytes [ 17, 5F ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtWriteFileGather 77F6F4E3 3 Bytes [ FF, 25, 1E ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtWriteFileGather + 4 77F6F4E7 2 Bytes [ 1C, 5F ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtWriteVirtualMemory 77F6F503 3 Bytes [ FF, 25, 1E ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] ntdll.dll!NtWriteVirtualMemory + 4 77F6F507 2 Bytes [ 28, 5F ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] kernel32.dll!LoadLibraryExW 77E6049B 6 Bytes JMP 5F070F5A
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] kernel32.dll!FreeLibrary + 11 77E60629 4 Bytes [ 0F, FA, 89, F9 ]
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] USER32.dll!SetWindowsHookExW 77D189C3 6 Bytes JMP 5F310F5A
.text D:\Daten_safe\Progs\Spyware-progs\gmer\gmer.exe[2144] USER32.dll!SetWindowsHookExA 77D18F56 6 Bytes JMP 5F2D0F5A
---- Devices - GMER 1.0.13 ----
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F974AAE5] xpdx.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [F95895A4] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [F958C6BE] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [F958CA5A] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [F958952C] avgntmgr.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F974B9B3] xpdx.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F974B9B3] xpdx.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F974B9B3] xpdx.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F974B9B3] xpdx.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F974B9B3] xpdx.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE [F95895A4] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_NAMED_PIPE [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLOSE [F958C6BE] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_READ [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_WRITE [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_EA [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL [F958CA5A] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_CREATE_MAILSLOT [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_SECURITY [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_SECURITY [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_POWER [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SYSTEM_CONTROL [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CHANGE [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_QUERY_QUOTA [F958952C] avgntmgr.sys
AttachedDevice \FileSystem\Fastfat \Fat IRP_MJ_SET_QUOTA [F958952C] avgntmgr.sys
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE F3ABF39A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE F3ABF39A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ F3ABF39A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION F3ABF39A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION F3ABF39A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION F3ABF39A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL F3ABF39A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL F3ABF39A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL F3ABF39A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN F3AC8866
Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL F3ABF39A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP F3ABF39A
Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP F3ABF39A
Device \FileSystem\Cdfs \Cdfs FastIoCheckIfPossible F3AC87FC
---- Registry - GMER 1.0.13 ----
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@Start 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@ImagePath \??\C:\WINDOWS\System32\xpdx.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@DisplayName xpdx system driver
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@Group Base
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@ExtParamD 0xB2 0xDA 0xB5 0x1F ...
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx\Security
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@Start 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@ImagePath \??\C:\WINDOWS\System32\xpdx.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@DisplayName xpdx system driver
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@Group Base
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@ExtParamD 0xB2 0xDA 0xB5 0x1F ...
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx\Enum
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@Start 1
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@ImagePath \??\C:\WINDOWS\System32\xpdx.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@DisplayName xpdx system driver
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@Group Base
Reg \Registry\MACHINE\SYSTEM\ControlSet001\Services\xpdx@ExtParamD 0xB2 0xDA 0xB5 0x1F ...
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx@Start 1
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx@ImagePath \??\C:\WINDOWS\System32\xpdx.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx@DisplayName xpdx system driver
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx@Group Base
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx@ExtParamD 0xB2 0xDA 0xB5 0x1F ...
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx\Security
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx@Type 1
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx@Start 1
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx@ImagePath \??\C:\WINDOWS\System32\xpdx.sys
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx@DisplayName xpdx system driver
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx@Group Base
Reg \Registry\MACHINE\SYSTEM\ControlSet002\Services\xpdx@ExtParamD 0xB2 0xDA 0xB5 0x1F ...
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@Type 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@Start 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@ImagePath \??\C:\WINDOWS\System32\xpdx.sys
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@DisplayName xpdx system driver
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@Group Base
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@ExtParamD 0xB2 0xDA 0xB5 0x1F ...
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx\Security
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@Type 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@Start 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@ImagePath \??\C:\WINDOWS\System32\xpdx.sys
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@DisplayName xpdx system driver
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@Group Base
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@ExtParamD 0xB2 0xDA 0xB5 0x1F ...
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx\Enum
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@Type 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@Start 1
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@ErrorControl 0
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@ImagePath \??\C:\WINDOWS\System32\xpdx.sys
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@DisplayName xpdx system driver
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@Group Base
Reg \Registry\MACHINE\SYSTEM\CurrentControlSet\Services\xpdx@ExtParamD 0xB2 0xDA 0xB5 0x1F ...
---- EOF - GMER 1.0.13 ----
Catchme: