I have split the log into three posts:
GMER 1.0.15.15020 [jd4x649l.exe] -
http://www.gmer.net
Rootkit scan 2009-08-11 09:44:05
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwClose [0xBA767818]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwCreateKey [0xBA7677D0]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwCreatePagingFile [0xBA75BA20]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateKey [0xBA75C2A8]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateValueKey [0xBA767910]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwOpenKey [0xBA767794]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwQueryKey [0xBA75C2C8]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwQueryValueKey [0xBA767866]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwSetSystemPowerState [0xBA7670B0]
Code 8A483500 pIofCallDriver
---- Kernel code sections - GMER 1.0.15 ----
.text ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
---- User code sections - GMER 1.0.15 ----
.text I:\Program Files\Java\jre6\bin\jqs.exe[204] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Program Files\Java\jre6\bin\jqs.exe[204] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Program Files\Java\jre6\bin\jqs.exe[204] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Program Files\Java\jre6\bin\jqs.exe[204] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Program Files\Java\jre6\bin\jqs.exe[204] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Program Files\Java\jre6\bin\jqs.exe[204] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\RTHDCPL.EXE[208] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\RTHDCPL.EXE[208] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\RTHDCPL.EXE[208] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\RTHDCPL.EXE[208] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\RTHDCPL.EXE[208] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\RTHDCPL.EXE[208] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Program Files\LS_Duhem\lsdiorw\lsdiorw.exe[280] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Program Files\LS_Duhem\lsdiorw\lsdiorw.exe[280] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Program Files\LS_Duhem\lsdiorw\lsdiorw.exe[280] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Program Files\LS_Duhem\lsdiorw\lsdiorw.exe[280] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Program Files\LS_Duhem\lsdiorw\lsdiorw.exe[280] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Program Files\LS_Duhem\lsdiorw\lsdiorw.exe[280] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\System32\alg.exe[572] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\System32\alg.exe[572] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\System32\alg.exe[572] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\System32\alg.exe[572] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\System32\alg.exe[572] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\System32\alg.exe[572] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\System32\nvsvc32.exe[668] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\System32\nvsvc32.exe[668] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\System32\nvsvc32.exe[668] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\System32\nvsvc32.exe[668] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\System32\nvsvc32.exe[668] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\System32\nvsvc32.exe[668] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\system32\IoctlSvc.exe[704] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\system32\IoctlSvc.exe[704] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\system32\IoctlSvc.exe[704] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\system32\IoctlSvc.exe[704] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\system32\IoctlSvc.exe[704] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\system32\IoctlSvc.exe[704] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\system32\PnkBstrA.exe[720] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\system32\PnkBstrA.exe[720] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\system32\PnkBstrA.exe[720] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\system32\PnkBstrA.exe[720] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\system32\PnkBstrA.exe[720] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\system32\PnkBstrA.exe[720] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\system32\winlogon.exe[760] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FF948C4
.text I:\WINDOWS\system32\winlogon.exe[760] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FF94953
.text I:\WINDOWS\system32\winlogon.exe[760] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FF94960
.text I:\WINDOWS\system32\winlogon.exe[760] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FF94BE4
.text I:\WINDOWS\system32\winlogon.exe[760] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FF94949
.text I:\WINDOWS\system32\winlogon.exe[760] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FF949A1
.text I:\WINDOWS\system32\services.exe[804] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FF948C4
.text I:\WINDOWS\system32\services.exe[804] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FF94953
.text I:\WINDOWS\system32\services.exe[804] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FF94960
.text I:\WINDOWS\system32\services.exe[804] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FF94BE4
.text I:\WINDOWS\system32\services.exe[804] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FF94949
.text I:\WINDOWS\system32\services.exe[804] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FF949A1
.text I:\WINDOWS\system32\lsass.exe[820] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FF948C4
.text I:\WINDOWS\system32\lsass.exe[820] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FF94953
.text I:\WINDOWS\system32\lsass.exe[820] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FF94960
.text I:\WINDOWS\system32\lsass.exe[820] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FF94BE4
.text I:\WINDOWS\system32\lsass.exe[820] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FF94949
.text I:\WINDOWS\system32\lsass.exe[820] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FF949A1
.text I:\WINDOWS\system32\svchost.exe[988] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\system32\svchost.exe[988] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\system32\svchost.exe[988] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\system32\svchost.exe[988] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\system32\svchost.exe[988] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\system32\svchost.exe[988] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\system32\wscntfy.exe[1048] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\system32\wscntfy.exe[1048] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\system32\wscntfy.exe[1048] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\system32\wscntfy.exe[1048] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\system32\wscntfy.exe[1048] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\system32\wscntfy.exe[1048] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1116] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1116] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1116] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1116] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1116] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1116] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\System32\svchost.exe[1152] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FF848C4
.text I:\WINDOWS\System32\svchost.exe[1152] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FF84953
.text I:\WINDOWS\System32\svchost.exe[1152] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FF84960
.text I:\WINDOWS\System32\svchost.exe[1152] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FF84BE4
.text I:\WINDOWS\System32\svchost.exe[1152] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FF84949
.text I:\WINDOWS\System32\svchost.exe[1152] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FF849A1
.text I:\WINDOWS\System32\svchost.exe[1192] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\System32\svchost.exe[1192] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\System32\svchost.exe[1192] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\System32\svchost.exe[1192] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\System32\svchost.exe[1192] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\System32\svchost.exe[1192] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\System32\svchost.exe[1240] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\System32\svchost.exe[1240] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\System32\svchost.exe[1240] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\System32\svchost.exe[1240] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\System32\svchost.exe[1240] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\System32\svchost.exe[1240] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\System32\svchost.exe[1316] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\System32\svchost.exe[1316] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\System32\svchost.exe[1316] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\System32\svchost.exe[1316] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\System32\svchost.exe[1316] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\System32\svchost.exe[1316] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
? I:\WINDOWS\System32\svchost.exe[1440] image checksum mismatch; number of sections mismatch; time/date stamp mismatch;
.text I:\WINDOWS\System32\svchost.exe[1440] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\System32\svchost.exe[1440] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\System32\svchost.exe[1440] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\System32\svchost.exe[1440] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\System32\svchost.exe[1440] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\System32\svchost.exe[1440] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\system32\spoolsv.exe[1496] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\system32\spoolsv.exe[1496] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\system32\spoolsv.exe[1496] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\system32\spoolsv.exe[1496] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\system32\spoolsv.exe[1496] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\system32\spoolsv.exe[1496] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Program Files\Canon\CAL\CALMAIN.exe[1704] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Program Files\Canon\CAL\CALMAIN.exe[1704] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Program Files\Canon\CAL\CALMAIN.exe[1704] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Program Files\Canon\CAL\CALMAIN.exe[1704] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Program Files\Canon\CAL\CALMAIN.exe[1704] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Program Files\Canon\CAL\CALMAIN.exe[1704] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
? I:\WINDOWS\System32\svchost.exe[1804] image checksum mismatch; number of sections mismatch; time/date stamp mismatch;
.text I:\WINDOWS\System32\svchost.exe[1804] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\System32\svchost.exe[1804] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\System32\svchost.exe[1804] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\System32\svchost.exe[1804] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\System32\svchost.exe[1804] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\System32\svchost.exe[1804] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1864] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1864] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1864] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1864] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1864] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[1864] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Program Files\Bonjour\mDNSResponder.exe[1880] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Program Files\Bonjour\mDNSResponder.exe[1880] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Program Files\Bonjour\mDNSResponder.exe[1880] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Program Files\Bonjour\mDNSResponder.exe[1880] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Program Files\Bonjour\mDNSResponder.exe[1880] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Program Files\Bonjour\mDNSResponder.exe[1880] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.reloc I:\WINDOWS\Explorer.EXE[1912] I:\WINDOWS\Explorer.EXE section is executable [0x010FB000, 0x8800, 0xE0000040]
.reloc I:\WINDOWS\Explorer.EXE[1912] I:\WINDOWS\Explorer.EXE entry point in ".reloc" section [0x010FE985]
.text I:\WINDOWS\Explorer.EXE[1912] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\Explorer.EXE[1912] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\Explorer.EXE[1912] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\Explorer.EXE[1912] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\Explorer.EXE[1912] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\Explorer.EXE[1912] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1916] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1916] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1916] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1916] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1916] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1916] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1916] kernel32.dll!SetUnhandledExceptionFilter 7C810386 4 Bytes [C2, 04, 00, 00]
.text I:\Program Files\Java\jre6\bin\jusched.exe[2064] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Program Files\Java\jre6\bin\jusched.exe[2064] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Program Files\Java\jre6\bin\jusched.exe[2064] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Program Files\Java\jre6\bin\jusched.exe[2064] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Program Files\Java\jre6\bin\jusched.exe[2064] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Program Files\Java\jre6\bin\jusched.exe[2064] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[2088] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[2088] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[2088] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[2088] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[2088] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe[2088] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Program Files\zMUD\Zmud.exe[2168] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Program Files\zMUD\Zmud.exe[2168] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Program Files\zMUD\Zmud.exe[2168] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Program Files\zMUD\Zmud.exe[2168] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Program Files\zMUD\Zmud.exe[2168] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Program Files\zMUD\Zmud.exe[2168] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe[2332] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe[2332] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe[2332] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe[2332] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe[2332] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe[2332] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
? I:\WINDOWS\System32\svchost.exe[2568] image checksum mismatch; number of sections mismatch; time/date stamp mismatch;
.text I:\WINDOWS\System32\svchost.exe[2568] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\System32\svchost.exe[2568] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\System32\svchost.exe[2568] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\System32\svchost.exe[2568] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\System32\svchost.exe[2568] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\System32\svchost.exe[2568] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\system32\svchost.exe[2592] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\system32\svchost.exe[2592] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\system32\svchost.exe[2592] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\system32\svchost.exe[2592] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\system32\svchost.exe[2592] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\system32\svchost.exe[2592] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
? I:\WINDOWS\System32\svchost.exe[3776] image checksum mismatch; number of sections mismatch; time/date stamp mismatch; unknown module: gdiplus.dllunknown module: OLEAUT32.dll
.text I:\WINDOWS\System32\svchost.exe[3776] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\System32\svchost.exe[3776] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\System32\svchost.exe[3776] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\System32\svchost.exe[3776] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\System32\svchost.exe[3776] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\System32\svchost.exe[3776] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\system32\svchost.exe[4248] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\system32\svchost.exe[4248] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\system32\svchost.exe[4248] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\system32\svchost.exe[4248] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\system32\svchost.exe[4248] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\system32\svchost.exe[4248] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Program Files\zMUD\Zmud.exe[4548] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Program Files\zMUD\Zmud.exe[4548] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Program Files\zMUD\Zmud.exe[4548] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Program Files\zMUD\Zmud.exe[4548] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Program Files\zMUD\Zmud.exe[4548] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Program Files\zMUD\Zmud.exe[4548] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\WINDOWS\System32\reader_s.exe[4600] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\System32\reader_s.exe[4600] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\System32\reader_s.exe[4600] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\System32\reader_s.exe[4600] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\System32\reader_s.exe[4600] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\System32\reader_s.exe[4600] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Documents and Settings\Nat\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe[4612] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Documents and Settings\Nat\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe[4612] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Documents and Settings\Nat\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe[4612] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Documents and Settings\Nat\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe[4612] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Documents and Settings\Nat\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe[4612] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Documents and Settings\Nat\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe[4612] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Documents and Settings\Nat\Desktop\jd4x649l.exe[4904] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Documents and Settings\Nat\Desktop\jd4x649l.exe[4904] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Documents and Settings\Nat\Desktop\jd4x649l.exe[4904] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Documents and Settings\Nat\Desktop\jd4x649l.exe[4904] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Documents and Settings\Nat\Desktop\jd4x649l.exe[4904] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Documents and Settings\Nat\Desktop\jd4x649l.exe[4904] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
? I:\WINDOWS\System32\svchost.exe[5288] image checksum mismatch; number of sections mismatch; time/date stamp mismatch; unknown module: gdiplus.dllunknown module: OLEAUT32.dll
.text I:\WINDOWS\System32\svchost.exe[5288] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\WINDOWS\System32\svchost.exe[5288] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\WINDOWS\System32\svchost.exe[5288] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\WINDOWS\System32\svchost.exe[5288] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\WINDOWS\System32\svchost.exe[5288] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\WINDOWS\System32\svchost.exe[5288] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Program Files\Mozilla Firefox\firefox.exe[5444] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Program Files\Mozilla Firefox\firefox.exe[5444] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Program Files\Mozilla Firefox\firefox.exe[5444] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Program Files\Mozilla Firefox\firefox.exe[5444] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Program Files\Mozilla Firefox\firefox.exe[5444] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Program Files\Mozilla Firefox\firefox.exe[5444] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
.text I:\Program Files\Azureus\Azureus.exe[5900] ntdll.dll!NtCreateFile 7C90D682 5 Bytes CALL 7FFA48C4
.text I:\Program Files\Azureus\Azureus.exe[5900] ntdll.dll!NtCreateProcess 7C90D754 5 Bytes CALL 7FFA4953
.text I:\Program Files\Azureus\Azureus.exe[5900] ntdll.dll!NtCreateProcessEx 7C90D769 5 Bytes CALL 7FFA4960
.text I:\Program Files\Azureus\Azureus.exe[5900] ntdll.dll!NtDeviceIoControlFile 7C90D8E3 5 Bytes CALL 7FFA4BE4
.text I:\Program Files\Azureus\Azureus.exe[5900] ntdll.dll!NtOpenFile 7C90DCFD 5 Bytes CALL 7FFA4949
.text I:\Program Files\Azureus\Azureus.exe[5900] ntdll.dll!NtQueryInformationProcess 7C90E01B 5 Bytes CALL 7FFA49A1
---- User IAT/EAT - GMER 1.0.15 ----
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!RegQueryValueExW] CB8401C7
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!SetSecurityDescriptorDacl] 4CE90043
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!SetEntriesInAclW] 560001D0
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!SetSecurityDescriptorGroup] 06C7F18B
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!SetSecurityDescriptorOwner] [0043CB84] I:\WINDOWS\System32\svchost.exe (Generic Host Process for Win32 Services/Microsoft Corporation)
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!InitializeSecurityDescriptor] 01D03EE8
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!GetTokenInformation] 2444F600
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!OpenProcessToken] 07740108
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!OpenThreadToken] D3BDE856
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!SetServiceStatus] 8B590001
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!RegisterServiceCtrlHandlerW] 04C25EC6
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!RegCloseKey] EC8B5500
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!RegOpenKeyExW] FF1475FF
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [ADVAPI32.dll!StartServiceCtrlDispatcherW] 75FF1075
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!WideCharToMultiByte] 5D10C483
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!lstrlenW] EC8B55C3
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LocalFree] FF1475FF
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetCurrentProcess] 75FF1075
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetCurrentThread] 0875FF0C
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetProcAddress] 01D8B9E8
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LoadLibraryExW] 08458B00
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LCMapStringW] 021F05E8
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!FreeLibrary] 89F18B00
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!lstrcpyW] 0DE8F075
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!ExpandEnvironmentStringsW] 830001CF
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!lstrcmpiW] FF00FC65
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!ExitProcess] 4E8D0875
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetCommandLineW] 9006C70C
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!InitializeCriticalSection] E80043CB
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetProcessHeap] 00001D70
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!SetErrorMode] B7E8C68B
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!SetUnhandledExceptionFilter] C200021F
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!RegisterWaitForSingleObject] 8B560004
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!InterlockedCompareExchange] 6A006AF1
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LoadLibraryA] 0C4E8D01
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!QueryPerformanceCounter] CB9006C7
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetTickCount] BAE80043
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetCurrentThreadId] 8B000022
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetCurrentProcessId] A0E95ECE
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!GetSystemTimeAsFileTime] 830001CF
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!TerminateProcess] 72102479
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!UnhandledExceptionFilter] 10418B04
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!LocalAlloc] 10418DC3
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!lstrcmpW] F18B56C3
IAT I:\WINDOWS\System32\svchost.exe[1440] @ I:\WINDOWS\System32\svchost.exe [KERNEL32.dll!DelayLoadFailureHook] FFFFCDE8