GMER Output
GMER Output:
GMER 1.0.15.14972 -
http://www.gmer.net
Rootkit scan 2009-06-01 22:01:05
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xA16036B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xA1603574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xA1603A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xA160314C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xA160364E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xA160308C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xA16030F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xA160376E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xA160372E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xA16038AE]
---- User code sections - GMER 1.0.15 ----
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[296] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[296] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[296] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[296] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[296] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[296] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[296] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[296] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[296] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[296] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[296] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[296] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashServ.exe[296] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[504] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[504] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[504] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[504] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[504] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[504] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[504] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[504] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[504] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[504] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[504] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[504] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgnsx.exe[504] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[948] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[948] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[948] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[948] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[948] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[948] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[948] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[948] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[948] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[948] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[948] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[948] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe[948] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe[1204] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe[1204] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe[1204] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe[1204] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe[1204] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe[1204] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe[1204] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe[1204] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe[1204] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe[1204] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe[1204] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe[1204] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe[1204] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[1240] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[1240] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[1240] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[1240] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[1240] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[1240] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[1240] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[1240] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[1240] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[1240] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[1240] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[1240] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Microsoft ActiveSync\wcescomm.exe[1240] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1596] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1596] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1596] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1596] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1596] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1596] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1596] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1596] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1596] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1596] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1596] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1596] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe[1596] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2336] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2336] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2336] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2336] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2336] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2336] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2336] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2336] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2336] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2336] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2336] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2336] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe[2336] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2408] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2408] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2408] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2408] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2408] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2408] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2408] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2408] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2408] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2408] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2408] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2408] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Alwil Software\Avast4\ashWebSv.exe[2408] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[2464] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[2464] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[2464] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[2464] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[2464] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[2464] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[2464] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[2464] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[2464] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[2464] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[2464] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[2464] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe[2464] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE[2768] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 0091018D C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE[2768] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 00910089 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE[2768] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 0090FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE[2768] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00911D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE[2768] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00911B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE[2768] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 00911EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE[2768] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 00913394 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE[2768] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 009111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE[2768] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 009108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE[2768] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 00912E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE[2768] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 009103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE[2768] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 00912913 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE[2768] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 00910933 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[2956] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[2956] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[2956] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[2956] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[2956] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[2956] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[2956] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[2956] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[2956] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[2956] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[2956] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[2956] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe[2956] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[2964] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[2964] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[2964] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[2964] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[2964] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[2964] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[2964] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[2964] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[2964] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[2964] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[2964] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[2964] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe[2964] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\Documents and Settings\Geoff\Desktop\gmer.exe[3068] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\Documents and Settings\Geoff\Desktop\gmer.exe[3068] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\Documents and Settings\Geoff\Desktop\gmer.exe[3068] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\Documents and Settings\Geoff\Desktop\gmer.exe[3068] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\Documents and Settings\Geoff\Desktop\gmer.exe[3068] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\Documents and Settings\Geoff\Desktop\gmer.exe[3068] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\Documents and Settings\Geoff\Desktop\gmer.exe[3068] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\Documents and Settings\Geoff\Desktop\gmer.exe[3068] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\Documents and Settings\Geoff\Desktop\gmer.exe[3068] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\Documents and Settings\Geoff\Desktop\gmer.exe[3068] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\Documents and Settings\Geoff\Desktop\gmer.exe[3068] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\Documents and Settings\Geoff\Desktop\gmer.exe[3068] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\Documents and Settings\Geoff\Desktop\gmer.exe[3068] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe[3124] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe[3124] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe[3124] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe[3124] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe[3124] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe[3124] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe[3124] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe[3124] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe[3124] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe[3124] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe[3124] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe[3124] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe[3124] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[3208] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[3208] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[3208] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[3208] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[3208] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[3208] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[3208] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[3208] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[3208] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[3208] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[3208] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[3208] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Common Files\Real\Update_OB\realsched.exe[3208] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Java\j2re1.4.2_10\bin\jusched.exe[3236] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Java\j2re1.4.2_10\bin\jusched.exe[3236] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Java\j2re1.4.2_10\bin\jusched.exe[3236] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Java\j2re1.4.2_10\bin\jusched.exe[3236] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Java\j2re1.4.2_10\bin\jusched.exe[3236] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Java\j2re1.4.2_10\bin\jusched.exe[3236] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Java\j2re1.4.2_10\bin\jusched.exe[3236] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Java\j2re1.4.2_10\bin\jusched.exe[3236] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Java\j2re1.4.2_10\bin\jusched.exe[3236] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Java\j2re1.4.2_10\bin\jusched.exe[3236] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Java\j2re1.4.2_10\bin\jusched.exe[3236] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Java\j2re1.4.2_10\bin\jusched.exe[3236] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\Program Files\Java\j2re1.4.2_10\bin\jusched.exe[3236] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3304] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 01E6018D C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3304] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 01E5FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3304] WS2_32.dll!send 71AB4C27 5 Bytes JMP 01E61D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3304] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 01E61B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3304] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 01E61EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3304] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 01E63394 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3304] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 01E611F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3304] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 01E608B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3304] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 01E62E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3304] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 01E603FD C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3304] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 01E62913 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3304] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 01E60933 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\AVG\AVG8\avgtray.exe[3304] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 01E60089 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3376] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3376] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3376] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3376] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3376] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3376] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3376] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3376] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3376] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3376] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3376] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3376] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe[3376] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\MICROS~4\rapimgr.exe[3644] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 1001018D C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\MICROS~4\rapimgr.exe[3644] ADVAPI32.dll!RegEnumValueW 77DD7EED 5 Bytes JMP 1000FD7B C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\MICROS~4\rapimgr.exe[3644] WS2_32.dll!send 71AB4C27 5 Bytes JMP 10011D21 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\MICROS~4\rapimgr.exe[3644] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 10011B22 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\MICROS~4\rapimgr.exe[3644] CRYPT32.dll!PFXImportCertStore 77AEFF8F 5 Bytes JMP 10010089 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\MICROS~4\rapimgr.exe[3644] WININET.dll!HttpOpenRequestA 78064321 5 Bytes JMP 10011EC8 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\MICROS~4\rapimgr.exe[3644] WININET.dll!InternetConnectA 7806497A 5 Bytes JMP 10013394 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\MICROS~4\rapimgr.exe[3644] WININET.dll!InternetReadFile 7806ABB4 5 Bytes JMP 100111F7 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\MICROS~4\rapimgr.exe[3644] WININET.dll!InternetQueryDataAvailable 7806ADF5 5 Bytes JMP 100108B9 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\MICROS~4\rapimgr.exe[3644] WININET.dll!HttpSendRequestA 7806CD40 5 Bytes JMP 10012E4F C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\MICROS~4\rapimgr.exe[3644] WININET.dll!InternetSetStatusCallback 7807288F 5 Bytes JMP 100103FD C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\MICROS~4\rapimgr.exe[3644] WININET.dll!HttpSendRequestW 7808082D 5 Bytes JMP 10012913 C:\WINDOWS\system32\ms32clod.dll
.text C:\PROGRA~1\MICROS~4\rapimgr.exe[3644] WININET.dll!InternetReadFileExA 78082AEA 5 Bytes JMP 10010933 C:\WINDOWS\system32\ms32clod.dll
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\WINDOWS\system32\services.exe[984] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00390002
IAT C:\WINDOWS\system32\services.exe[984] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00390000
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 mouclass.sys (Mouse Class Driver/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software)
Device \Driver\BTHUSB \Device\00000091 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000093 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp aswRdr.SYS (avast! TDI RDR Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0020e07b3953
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0020e07b3953@0012d21189ba 0xB4 0x00 0xA7 0xAC ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0020e07b3953@0017830a4c5d 0x7F 0xD0 0x96 0x1D ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0020e07b3953
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0020e07b3953@0012d21189ba 0xB4 0x00 0xA7 0xAC ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0020e07b3953@0017830a4c5d 0x7F 0xD0 0x96 0x1D ...
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@AppInit_DLLs SYS:Microsoft\Windows NT\CurrentVersion\Windows
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@Beep #USR:Control Panel\Sound
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@BorderWidth #USR:Control Panel\Desktop\WindowMetrics
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@CoolSwitch USR:Control Panel\Desktop
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@CursorBlinkRate #USR:Control Panel\Desktop
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@DefaultSeparateVDM \Registry\Machine\System\CurrentControlSet\Control\WOW
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@DeviceNotSelectedTimeout #SYS:Microsoft\Windows NT\CurrentVersion\Windows
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@DoubleClickHeight #USR:Control Panel\Mouse
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@DoubleClickSpeed #USR:Control Panel\Mouse
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@DoubleClickWidth #USR:Control Panel\Mouse
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@DragFullWindows USR:Control Panel\Desktop
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@InitialKeyboardIndicators USR:Control Panel\Keyboard
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@KeyboardDelay #USR:Control Panel\Keyboard
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@KeyboardSpeed #USR:Control Panel\Keyboard
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@LowPowerActive #USR:Control Panel\Desktop
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@LowPowerTimeOut #USR:Control Panel\Desktop
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@MouseSpeed #USR:Control Panel\Mouse
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@MouseThreshold1 #USR:Control Panel\Mouse
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@MouseThreshold2 #USR:Control Panel\Mouse
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@PowerOffActive #USR:Control Panel\Desktop
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@PowerOffTimeOut #USR:Control Panel\Desktop
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@ScreenSaveActive #USR:Control Panel\Desktop
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@ScreenSaveTimeOut #USR:Control Panel\Desktop
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@SnapToDefaultButton #USR:Control Panel\Mouse
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@Spooler #SYS:Microsoft\Windows NT\CurrentVersion\Windows
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@swapdisk SYS:Microsoft\Windows NT\CurrentVersion\Windows
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@SwapMouseButtons #USR:Control Panel\Mouse
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini\Windows@TransmissionRetryTimeout #SYS:Microsoft\Windows NT\CurrentVersion\Windows
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs ms32clod.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1
---- EOF - GMER 1.0.15 ----