GMER 1.0.12.12086 - http://www.gmer.net Rootkit scan 2007-04-12 21:33:34 Windows 5.1.2600 Dodatek Service Pack 2 ---- System - GMER 1.0.12 ---- SSDT Vax347b.sys ZwClose SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwCreateKey SSDT Vax347b.sys ZwCreatePagingFile SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwDeleteKey SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwDeleteValueKey SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwEnumerateKey SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwEnumerateValueKey SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwOpenKey SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwQueryKey SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwQueryValueKey SSDT Vax347b.sys ZwSetSystemPowerState SSDT \SystemRoot\System32\Drivers\ShldDrv.SYS ZwSetValueKey SSDT ??\C:\WINDOWS\system32\DRIVERS\PavProc.sys ZwTerminateProcess SSDT ??\C:\WINDOWS\system32\DRIVERS\PavProc.sys ZwTerminateThread SSDT ??\C:\WINDOWS\system32\PavSRK.sys ZwWriteVirtualMemory ---- Kernel code sections - GMER 1.0.12 ---- ? C:\WINDOWS\system32\PavSRK.sys Nie można odnaleźć określonego pliku. ? C:\WINDOWS\system32\PavTPK.sys Nie można odnaleźć określonego pliku. ? system32\drivers\av5flt.sys Nie można odnaleźć określonego pliku. ? C:\WINDOWS\system32\DRIVERS\COMFiltr.sys Nie można odnaleźć określonego pliku. ---- User code sections - GMER 1.0.12 ---- .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ntdll.dll!NtClose 7C90D586 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ntdll.dll!NtClose + 4 7C90D58A 2 Bytes [4A, 5F] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ntdll.dll!NtCreateFile 7C90D682 1 Byte [FF] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ntdll.dll!NtCreateFile + 2 7C90D684 1 Byte [1E] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ntdll.dll!NtCreateFile + 4 7C90D686 2 Bytes [6B, 5F] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ntdll.dll!NtCreateKey 7C90D6D6 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ntdll.dll!NtCreateKey + 4 7C90D6DA 2 Bytes [4D, 5F] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ntdll.dll!NtDeleteFile 7C90D88F 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ntdll.dll!NtDeleteFile + 4 7C90D893 2 Bytes [6E, 5F] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ntdll.dll!NtDeleteKey 7C90D8A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ntdll.dll!NtDeleteKey + 4 7C90D8A8 2 Bytes [50, 5F] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] USER32.dll!TranslateMessage 7E368BF6 6 Bytes JMP 5F910F5A .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] USER32.dll!DispatchMessageA 7E3696B8 6 Bytes JMP 5F8E0F5A .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] USER32.dll!GetKeyState 7E36C505 6 Bytes JMP 5F9D0F5A .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] USER32.dll!BeginDeferWindowPos 7E36D907 6 Bytes JMP 5F8B0F5A .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] USER32.dll!GetKeyboardState 7E36EF29 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] USER32.dll!GetKeyboardState + 4 7E36EF2D 2 Bytes [9B, 5F] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] USER32.dll!GetAsyncKeyState 7E36F3B3 6 Bytes JMP 5F940F5A .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] USER32.dll!CreateAcceleratorTableW 7E37D3C1 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] USER32.dll!CreateAcceleratorTableW + 4 7E37D3C5 2 Bytes [A1, 5F] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] USER32.dll!SetWindowsHookExW 7E37DDB5 6 Bytes JMP 5FA30F5A .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] USER32.dll!SetWindowsHookExA 7E3811D1 6 Bytes JMP 5F880F5A .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] USER32.dll!AttachThreadInput 7E381E12 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] USER32.dll!AttachThreadInput + 4 7E381E16 2 Bytes [98, 5F] .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ole32.dll!CoCreateInstanceEx 774EFA6B 6 Bytes JMP 5F850F5A .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ole32.dll!CoGetClassObject 77505DB2 6 Bytes JMP 5F820F5A .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ole32.dll!CLSIDFromProgID 775142CC 6 Bytes JMP 5F7F0F5A .text C:\Program Files\MicroStar\WLANUtility\WlanUtility.exe[1136] ole32.dll!CLSIDFromProgIDEx 775461FE 6 Bytes JMP 5F7C0F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtClose 7C90D586 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtClose + 4 7C90D58A 2 Bytes [4A, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtCreateFile 7C90D682 1 Byte [FF] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtCreateFile + 2 7C90D684 1 Byte [1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtCreateFile + 4 7C90D686 2 Bytes [6B, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtCreateKey 7C90D6D6 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtCreateKey + 4 7C90D6DA 2 Bytes [4D, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtDeleteFile 7C90D88F 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtDeleteFile + 4 7C90D893 2 Bytes [6E, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtDeleteKey 7C90D8A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtDeleteKey + 4 7C90D8A8 2 Bytes [50, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtDeleteValueKey 7C90D8CE 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtDeleteValueKey + 4 7C90D8D2 2 Bytes [53, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtDuplicateObject 7C90D90D 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtDuplicateObject + 4 7C90D911 2 Bytes [56, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtEnumerateKey 7C90D94C 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtEnumerateKey + 4 7C90D950 2 Bytes [59, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtEnumerateValueKey 7C90D976 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtEnumerateValueKey + 4 7C90D97A 2 Bytes [5C, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtOpenFile 7C90DCFD 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtOpenFile + 4 7C90DD01 2 Bytes [71, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtQueryMultipleValueKey 7C90E0AE 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtQueryMultipleValueKey + 4 7C90E0B2 2 Bytes [5F, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtQueryValueKey 7C90E1FE 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtQueryValueKey + 4 7C90E202 2 Bytes [62, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtReadFile 7C90E27C 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtReadFile + 4 7C90E280 2 Bytes [74, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtSetInformationFile 7C90E5D9 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtSetInformationFile + 4 7C90E5DD 2 Bytes [77, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtSetValueKey 7C90E7BC 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtSetValueKey + 4 7C90E7C0 2 Bytes [65, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtUnloadKey 7C90E90C 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtUnloadKey + 4 7C90E910 2 Bytes [68, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtWriteFile 7C90E9F3 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!NtWriteFile + 4 7C90E9F7 2 Bytes [7A, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!LdrLoadDll 7C9161CA 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ntdll.dll!LdrLoadDll + 4 7C9161CE 2 Bytes [47, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F310F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] kernel32.dll!CreateFileMappingW 7C80938E 6 Bytes JMP 5F3A0F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] kernel32.dll!MapViewOfFileEx 7C80B896 6 Bytes JMP 5F340F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] kernel32.dll!CreateRemoteThread 7C81042C 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] kernel32.dll!CreateRemoteThread + 4 7C810430 2 Bytes [3E, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] kernel32.dll!CreateProcessInternalW 7C819513 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] kernel32.dll!CreateProcessInternalW + 4 7C819517 2 Bytes [44, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] kernel32.dll!MoveFileWithProgressW 7C81F72E 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] kernel32.dll!MoveFileWithProgressW + 4 7C81F732 2 Bytes [41, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] kernel32.dll!CopyFileExW 7C827B32 6 Bytes JMP 5F370F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!CloseServiceHandle 77DD5E4D 6 Bytes JMP 5F100F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!OpenServiceW 77DD6165 6 Bytes JMP 5F220F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!ControlService 77DDB635 6 Bytes JMP 5F130F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!OpenServiceA 77DDB88C 6 Bytes JMP 5F1F0F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!StartServiceW 77DDBBAC 6 Bytes JMP 5F280F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!StartServiceA 77DE3238 6 Bytes JMP 5F250F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!LsaAddAccountRights 77E0A9A1 6 Bytes JMP 5F2B0F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!LsaRemoveAccountRights 77E0AA41 6 Bytes JMP 5F2E0F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 6 Bytes JMP 5F040F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 6 Bytes JMP 5F070F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 6 Bytes JMP 5F0A0F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 6 Bytes JMP 5F0D0F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!CreateServiceA 77E27071 6 Bytes JMP 5F160F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!CreateServiceW 77E27209 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!CreateServiceW + 4 77E2720D 2 Bytes [1A, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ADVAPI32.dll!DeleteService 77E27311 6 Bytes JMP 5F1C0F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] USER32.dll!DispatchMessageW 7E368A01 6 Bytes JMP 5FA60F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] USER32.dll!TranslateMessage 7E368BF6 6 Bytes JMP 5F910F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] USER32.dll!DispatchMessageA 7E3696B8 6 Bytes JMP 5F8E0F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] USER32.dll!GetKeyState 7E36C505 6 Bytes JMP 5F9D0F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] USER32.dll!BeginDeferWindowPos 7E36D907 6 Bytes JMP 5F8B0F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] USER32.dll!GetKeyboardState 7E36EF29 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] USER32.dll!GetKeyboardState + 4 7E36EF2D 2 Bytes [9B, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] USER32.dll!GetAsyncKeyState 7E36F3B3 6 Bytes JMP 5F940F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] USER32.dll!CreateAcceleratorTableW 7E37D3C1 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] USER32.dll!CreateAcceleratorTableW + 4 7E37D3C5 2 Bytes [A1, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] USER32.dll!SetWindowsHookExW 7E37DDB5 6 Bytes JMP 5FA30F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] USER32.dll!SetWindowsHookExA 7E3811D1 6 Bytes JMP 5F880F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] USER32.dll!AttachThreadInput 7E381E12 3 Bytes [FF, 25, 1E] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] USER32.dll!AttachThreadInput + 4 7E381E16 2 Bytes [98, 5F] .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ole32.dll!CoCreateInstanceEx 774EFA6B 6 Bytes JMP 5F850F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ole32.dll!CoGetClassObject 77505DB2 6 Bytes JMP 5F820F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ole32.dll!CLSIDFromProgID 775142CC 6 Bytes JMP 5F7F0F5A .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe[1896] ole32.dll!CLSIDFromProgIDEx 775461FE 6 Bytes JMP 5F7C0F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtClose 7C90D586 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtClose + 4 7C90D58A 2 Bytes [4A, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtCreateFile 7C90D682 1 Byte [FF] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtCreateFile + 2 7C90D684 1 Byte [1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtCreateFile + 4 7C90D686 2 Bytes [6B, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtCreateKey 7C90D6D6 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtCreateKey + 4 7C90D6DA 2 Bytes [4D, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtDeleteFile 7C90D88F 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtDeleteFile + 4 7C90D893 2 Bytes [6E, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtDeleteKey 7C90D8A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtDeleteKey + 4 7C90D8A8 2 Bytes [50, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtDeleteValueKey 7C90D8CE 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtDeleteValueKey + 4 7C90D8D2 2 Bytes [53, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtDuplicateObject 7C90D90D 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtDuplicateObject + 4 7C90D911 2 Bytes [56, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtEnumerateKey 7C90D94C 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtEnumerateKey + 4 7C90D950 2 Bytes [59, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtEnumerateValueKey 7C90D976 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtEnumerateValueKey + 4 7C90D97A 2 Bytes [5C, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtOpenFile 7C90DCFD 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtOpenFile + 4 7C90DD01 2 Bytes [71, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtQueryMultipleValueKey 7C90E0AE 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtQueryMultipleValueKey + 4 7C90E0B2 2 Bytes [5F, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtQueryValueKey 7C90E1FE 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtQueryValueKey + 4 7C90E202 2 Bytes [62, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtReadFile 7C90E27C 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtReadFile + 4 7C90E280 2 Bytes [74, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtSetInformationFile 7C90E5D9 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtSetInformationFile + 4 7C90E5DD 2 Bytes [77, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtSetValueKey 7C90E7BC 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtSetValueKey + 4 7C90E7C0 2 Bytes [65, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtUnloadKey 7C90E90C 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtUnloadKey + 4 7C90E910 2 Bytes [68, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtWriteFile 7C90E9F3 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!NtWriteFile + 4 7C90E9F7 2 Bytes [7A, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!LdrLoadDll 7C9161CA 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ntdll.dll!LdrLoadDll + 4 7C9161CE 2 Bytes [47, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F310F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] kernel32.dll!CreateFileMappingW 7C80938E 6 Bytes JMP 5F3A0F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] kernel32.dll!MapViewOfFileEx 7C80B896 6 Bytes JMP 5F340F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] kernel32.dll!CreateRemoteThread 7C81042C 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] kernel32.dll!CreateRemoteThread + 4 7C810430 2 Bytes [3E, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] kernel32.dll!CreateProcessInternalW 7C819513 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] kernel32.dll!CreateProcessInternalW + 4 7C819517 2 Bytes [44, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] kernel32.dll!MoveFileWithProgressW 7C81F72E 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] kernel32.dll!MoveFileWithProgressW + 4 7C81F732 2 Bytes [41, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] kernel32.dll!CopyFileExW 7C827B32 6 Bytes JMP 5F370F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!CloseServiceHandle 77DD5E4D 6 Bytes JMP 5F100F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!OpenServiceW 77DD6165 6 Bytes JMP 5F220F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!ControlService 77DDB635 6 Bytes JMP 5F130F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!OpenServiceA 77DDB88C 6 Bytes JMP 5F1F0F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!StartServiceW 77DDBBAC 6 Bytes JMP 5F280F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!StartServiceA 77DE3238 6 Bytes JMP 5F250F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!LsaAddAccountRights 77E0A9A1 6 Bytes JMP 5F2B0F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!LsaRemoveAccountRights 77E0AA41 6 Bytes JMP 5F2E0F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 6 Bytes JMP 5F040F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 6 Bytes JMP 5F070F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 6 Bytes JMP 5F0A0F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 6 Bytes JMP 5F0D0F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!CreateServiceA 77E27071 6 Bytes JMP 5F160F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!CreateServiceW 77E27209 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!CreateServiceW + 4 77E2720D 2 Bytes [1A, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ADVAPI32.dll!DeleteService 77E27311 6 Bytes JMP 5F1C0F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] USER32.dll!DispatchMessageW 7E368A01 6 Bytes JMP 5FA60F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] USER32.dll!TranslateMessage 7E368BF6 6 Bytes JMP 5F910F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] USER32.dll!DispatchMessageA 7E3696B8 6 Bytes JMP 5F8E0F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] USER32.dll!GetKeyState 7E36C505 6 Bytes JMP 5F9D0F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] USER32.dll!BeginDeferWindowPos 7E36D907 6 Bytes JMP 5F8B0F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] USER32.dll!GetKeyboardState 7E36EF29 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] USER32.dll!GetKeyboardState + 4 7E36EF2D 2 Bytes [9B, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] USER32.dll!GetAsyncKeyState 7E36F3B3 6 Bytes JMP 5F940F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] USER32.dll!CreateAcceleratorTableW 7E37D3C1 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] USER32.dll!CreateAcceleratorTableW + 4 7E37D3C5 2 Bytes [A1, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] USER32.dll!SetWindowsHookExW 7E37DDB5 6 Bytes JMP 5FA30F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] USER32.dll!SetWindowsHookExA 7E3811D1 6 Bytes JMP 5F880F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] USER32.dll!AttachThreadInput 7E381E12 3 Bytes [FF, 25, 1E] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] USER32.dll!AttachThreadInput + 4 7E381E16 2 Bytes [98, 5F] .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ole32.dll!CoCreateInstanceEx 774EFA6B 6 Bytes JMP 5F850F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ole32.dll!CoGetClassObject 77505DB2 6 Bytes JMP 5F820F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ole32.dll!CLSIDFromProgID 775142CC 6 Bytes JMP 5F7F0F5A .text C:\Program Files\MicroStar\WLANUtility\WLAN_Service.exe[3200] ole32.dll!CLSIDFromProgIDEx 775461FE 6 Bytes JMP 5F7C0F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtClose 7C90D586 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtClose + 4 7C90D58A 2 Bytes [4C, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtCreateFile 7C90D682 1 Byte [FF] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtCreateFile + 2 7C90D684 1 Byte [1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtCreateFile + 4 7C90D686 2 Bytes [6D, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtCreateKey 7C90D6D6 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtCreateKey + 4 7C90D6DA 2 Bytes [4F, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtDeleteFile 7C90D88F 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtDeleteFile + 4 7C90D893 2 Bytes [70, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtDeleteKey 7C90D8A4 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtDeleteKey + 4 7C90D8A8 2 Bytes [52, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtDeleteValueKey 7C90D8CE 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtDeleteValueKey + 4 7C90D8D2 2 Bytes [55, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtDuplicateObject 7C90D90D 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtDuplicateObject + 4 7C90D911 2 Bytes [58, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtEnumerateKey 7C90D94C 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtEnumerateKey + 4 7C90D950 2 Bytes [5B, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtEnumerateValueKey 7C90D976 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtEnumerateValueKey + 4 7C90D97A 2 Bytes [5E, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtOpenFile 7C90DCFD 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtOpenFile + 4 7C90DD01 2 Bytes [73, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtQueryMultipleValueKey 7C90E0AE 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtQueryMultipleValueKey + 4 7C90E0B2 2 Bytes [61, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtQueryValueKey 7C90E1FE 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtQueryValueKey + 4 7C90E202 2 Bytes [64, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtReadFile 7C90E27C 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtReadFile + 4 7C90E280 2 Bytes [76, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtSetInformationFile 7C90E5D9 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtSetInformationFile + 4 7C90E5DD 2 Bytes [79, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtSetValueKey 7C90E7BC 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtSetValueKey + 4 7C90E7C0 2 Bytes [67, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtUnloadKey 7C90E90C 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtUnloadKey + 4 7C90E910 2 Bytes [6A, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtWriteFile 7C90E9F3 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!NtWriteFile + 4 7C90E9F7 2 Bytes [7C, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!LdrLoadDll 7C9161CA 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ntdll.dll!LdrLoadDll + 4 7C9161CE 2 Bytes [49, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F330F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] kernel32.dll!CreateFileMappingW 7C80938E 6 Bytes JMP 5F3C0F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] kernel32.dll!MapViewOfFileEx 7C80B896 6 Bytes JMP 5F360F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] kernel32.dll!CreateRemoteThread 7C81042C 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] kernel32.dll!CreateRemoteThread + 4 7C810430 2 Bytes [40, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] kernel32.dll!CreateProcessInternalW 7C819513 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] kernel32.dll!CreateProcessInternalW + 4 7C819517 2 Bytes [46, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] kernel32.dll!MoveFileWithProgressW 7C81F72E 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] kernel32.dll!MoveFileWithProgressW + 4 7C81F732 2 Bytes [43, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] kernel32.dll!CopyFileExW 7C827B32 6 Bytes JMP 5F390F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] USER32.dll!DispatchMessageW 7E368A01 6 Bytes JMP 5FA80F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] USER32.dll!TranslateMessage 7E368BF6 6 Bytes JMP 5F930F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] USER32.dll!DispatchMessageA 7E3696B8 6 Bytes JMP 5F900F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] USER32.dll!GetKeyState 7E36C505 6 Bytes JMP 5F9F0F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] USER32.dll!BeginDeferWindowPos 7E36D907 6 Bytes JMP 5F8D0F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] USER32.dll!GetKeyboardState 7E36EF29 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] USER32.dll!GetKeyboardState + 4 7E36EF2D 2 Bytes [9D, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] USER32.dll!GetAsyncKeyState 7E36F3B3 6 Bytes JMP 5F960F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] USER32.dll!CreateAcceleratorTableW 7E37D3C1 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] USER32.dll!CreateAcceleratorTableW + 4 7E37D3C5 2 Bytes [A3, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] USER32.dll!SetWindowsHookExW 7E37DDB5 6 Bytes JMP 5FA50F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] USER32.dll!SetWindowsHookExA 7E3811D1 6 Bytes JMP 5F8A0F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] USER32.dll!AttachThreadInput 7E381E12 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] USER32.dll!AttachThreadInput + 4 7E381E16 2 Bytes [9A, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!CloseServiceHandle 77DD5E4D 6 Bytes JMP 5F100F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!OpenServiceW 77DD6165 6 Bytes JMP 5F220F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!ControlService 77DDB635 6 Bytes JMP 5F130F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!OpenServiceA 77DDB88C 6 Bytes JMP 5F1F0F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!StartServiceW 77DDBBAC 6 Bytes JMP 5F2A0F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!StartServiceA 77DE3238 6 Bytes JMP 5F250F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!LsaAddAccountRights 77E0A9A1 6 Bytes JMP 5F2D0F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!LsaRemoveAccountRights 77E0AA41 6 Bytes JMP 5F300F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 6 Bytes JMP 5F040F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 6 Bytes JMP 5F070F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 6 Bytes JMP 5F0A0F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 6 Bytes JMP 5F0D0F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!CreateServiceA 77E27071 6 Bytes JMP 5F160F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!CreateServiceW 77E27209 3 Bytes [FF, 25, 1E] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!CreateServiceW + 4 77E2720D 2 Bytes [1A, 5F] .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ADVAPI32.dll!DeleteService 77E27311 6 Bytes JMP 5F1C0F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ole32.dll!CoCreateInstanceEx 774EFA6B 6 Bytes JMP 5F870F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ole32.dll!CoGetClassObject 77505DB2 6 Bytes JMP 5F840F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ole32.dll!CLSIDFromProgID 775142CC 6 Bytes JMP 5F810F5A .text C:\DOCUME~1\Blemer\USTAWI~1\Temp\Rar$EX00.484\gmer.exe[3212] ole32.dll!CLSIDFromProgIDEx 775461FE 6 Bytes JMP 5F7E0F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtClose 7C90D586 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtClose + 4 7C90D58A 2 Bytes [4A, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtCreateFile 7C90D682 1 Byte [FF] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtCreateFile + 2 7C90D684 1 Byte [1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtCreateFile + 4 7C90D686 2 Bytes [6B, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtCreateKey 7C90D6D6 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtCreateKey + 4 7C90D6DA 2 Bytes [4D, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtDeleteFile 7C90D88F 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtDeleteFile + 4 7C90D893 2 Bytes [6E, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtDeleteKey 7C90D8A4 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtDeleteKey + 4 7C90D8A8 2 Bytes [50, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtDeleteValueKey 7C90D8CE 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtDeleteValueKey + 4 7C90D8D2 2 Bytes [53, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtDuplicateObject 7C90D90D 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtDuplicateObject + 4 7C90D911 2 Bytes [56, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtEnumerateKey 7C90D94C 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtEnumerateKey + 4 7C90D950 2 Bytes [59, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtEnumerateValueKey 7C90D976 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtEnumerateValueKey + 4 7C90D97A 2 Bytes [5C, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtOpenFile 7C90DCFD 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtOpenFile + 4 7C90DD01 2 Bytes [71, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtQueryMultipleValueKey 7C90E0AE 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtQueryMultipleValueKey + 4 7C90E0B2 2 Bytes [5F, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtQueryValueKey 7C90E1FE 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtQueryValueKey + 4 7C90E202 2 Bytes [62, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtReadFile 7C90E27C 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtReadFile + 4 7C90E280 2 Bytes [74, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtSetInformationFile 7C90E5D9 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtSetInformationFile + 4 7C90E5DD 2 Bytes [77, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtSetValueKey 7C90E7BC 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtSetValueKey + 4 7C90E7C0 2 Bytes [65, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtUnloadKey 7C90E90C 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtUnloadKey + 4 7C90E910 2 Bytes [68, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtWriteFile 7C90E9F3 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!NtWriteFile + 4 7C90E9F7 2 Bytes [7A, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!LdrLoadDll 7C9161CA 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ntdll.dll!LdrLoadDll + 4 7C9161CE 2 Bytes [47, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] kernel32.dll!TerminateProcess 7C801E16 6 Bytes JMP 5F310F5A .text C:\Program Files\BitComet\BitComet.exe[3740] kernel32.dll!CreateFileMappingW 7C80938E 6 Bytes JMP 5F3A0F5A .text C:\Program Files\BitComet\BitComet.exe[3740] kernel32.dll!MapViewOfFileEx 7C80B896 6 Bytes JMP 5F340F5A .text C:\Program Files\BitComet\BitComet.exe[3740] kernel32.dll!CreateRemoteThread 7C81042C 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] kernel32.dll!CreateRemoteThread + 4 7C810430 2 Bytes [3E, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] kernel32.dll!CreateProcessInternalW 7C819513 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] kernel32.dll!CreateProcessInternalW + 4 7C819517 2 Bytes [44, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] kernel32.dll!MoveFileWithProgressW 7C81F72E 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] kernel32.dll!MoveFileWithProgressW + 4 7C81F732 2 Bytes [41, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] kernel32.dll!CopyFileExW 7C827B32 6 Bytes JMP 5F370F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!CloseServiceHandle 77DD5E4D 6 Bytes JMP 5F100F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!OpenServiceW 77DD6165 6 Bytes JMP 5F220F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!ControlService 77DDB635 6 Bytes JMP 5F130F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!OpenServiceA 77DDB88C 6 Bytes JMP 5F1F0F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!StartServiceW 77DDBBAC 6 Bytes JMP 5F280F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!StartServiceA 77DE3238 6 Bytes JMP 5F250F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!LsaAddAccountRights 77E0A9A1 6 Bytes JMP 5F2B0F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!LsaRemoveAccountRights 77E0AA41 6 Bytes JMP 5F2E0F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!ChangeServiceConfigA 77E26CC9 6 Bytes JMP 5F040F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!ChangeServiceConfigW 77E26E61 6 Bytes JMP 5F070F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!ChangeServiceConfig2A 77E26F61 6 Bytes JMP 5F0A0F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!ChangeServiceConfig2W 77E26FE9 6 Bytes JMP 5F0D0F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!CreateServiceA 77E27071 6 Bytes JMP 5F160F5A .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!CreateServiceW 77E27209 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!CreateServiceW + 4 77E2720D 2 Bytes [1A, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] ADVAPI32.dll!DeleteService 77E27311 6 Bytes JMP 5F1C0F5A .text C:\Program Files\BitComet\BitComet.exe[3740] USER32.dll!DispatchMessageW 7E368A01 6 Bytes JMP 5FA60F5A .text C:\Program Files\BitComet\BitComet.exe[3740] USER32.dll!TranslateMessage 7E368BF6 6 Bytes JMP 5F910F5A .text C:\Program Files\BitComet\BitComet.exe[3740] USER32.dll!DispatchMessageA 7E3696B8 6 Bytes JMP 5F8E0F5A .text C:\Program Files\BitComet\BitComet.exe[3740] USER32.dll!GetKeyState 7E36C505 6 Bytes JMP 5F9D0F5A .text C:\Program Files\BitComet\BitComet.exe[3740] USER32.dll!BeginDeferWindowPos 7E36D907 6 Bytes JMP 5F8B0F5A .text C:\Program Files\BitComet\BitComet.exe[3740] USER32.dll!GetKeyboardState 7E36EF29 3 Bytes [FF, 25, 1E] .text C:\Program Files\BitComet\BitComet.exe[3740] USER32.dll!GetKeyboardState + 4 7E36EF2D 2 Bytes [9B, 5F] .text C:\Program Files\BitComet\BitComet.exe[3740] USER32.dll!GetAsyn