merci pour les indications! çà a marché mieux que malware! je suis contente!!
voilà le rapport demandé:
GMER 1.0.14.14536 -
http://www.gmer.net
Rootkit scan 2009-02-20 12:05:45
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.14 ----
SSDT F7CAFD2C ZwCreateThread
SSDT F7CAFD18 ZwOpenProcess
SSDT F7CAFD1D ZwOpenThread
SSDT F7CAFD27 ZwTerminateProcess
SSDT F7CAFD22 ZwWriteVirtualMemory
Code E1C925F0 ZwEnumerateKey
Code E19450A8 ZwFlushInstructionCache
Code \WINDOWS\System32\drivers\fsndis5.sys (F-Secure Network Interceptor/F-Secure Corporation) IoCreateDevice
Code EE068EAB pIofCallDriver
---- Kernel code sections - GMER 1.0.14 ----
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805B6812 5 Bytes JMP E19450AC
PAGE ntkrnlpa.exe!ZwEnumerateKey 80623FD2 5 Bytes JMP E1C925F4
---- User code sections - GMER 1.0.14 ----
.text C:\Program Files\Securitoo\Av_Fw\Common\FSM32.EXE[164] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00F01FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Securitoo\Av_Fw\Common\FSM32.EXE[164] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00F02180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Windows Defender\MSASCui.exe[376] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 01941FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Windows Defender\MSASCui.exe[376] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 01942180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\csrss.exe[556] KERNEL32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 10001FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\csrss.exe[556] KERNEL32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 10002180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\winlogon.exe[580] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 016B1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\winlogon.exe[580] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 016B2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\services.exe[628] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00051FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\services.exe[628] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00052180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00F01FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\lsass.exe[640] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00F02180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[708] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 01581FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[708] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 01582180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Securitoo\Av_Fw\Anti-Virus\fsgk32st.exe[776] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00E01FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Securitoo\Av_Fw\Anti-Virus\fsgk32st.exe[776] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00E02180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\Ati2evxx.exe[816] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 01241FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\Ati2evxx.exe[816] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 01242180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[832] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00EB1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[832] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00EB2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[832] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 00E1000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[832] WS2_32.dll!connect 719F4A07 5 Bytes JMP 00E0000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[832] WS2_32.dll!send 719F4C27 5 Bytes JMP 00E2000A
.text C:\WINDOWS\system32\svchost.exe[836] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00AC1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\svchost.exe[836] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00AC2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Genie-Soft\GBALite8LaCie\GBMAgent.exe[884] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 01791FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Genie-Soft\GBALite8LaCie\GBMAgent.exe[884] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 01792180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\svchost.exe[928] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 01451FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\svchost.exe[928] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 01452180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[980] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00F11FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\ctfmon.exe[980] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00F12180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Windows Defender\MsMpEng.exe[1000] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00931FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Windows Defender\MsMpEng.exe[1000] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00932180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 033D1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\System32\svchost.exe[1040] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 033D2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\svchost.exe[1124] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00C81FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\svchost.exe[1124] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00C82180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00DC1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\svchost.exe[1196] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00DC2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[1344] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 01B11FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\spoolsv.exe[1344] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 01B12180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\a-squared Free\a2service.exe[1580] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 011D1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\a-squared Free\a2service.exe[1580] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 011D2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 014B1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 014B2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\Ati2evxx.exe[1720] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 01251FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\Ati2evxx.exe[1720] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 01252180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\PROGRA~1\SECURI~1\Av_Fw\backweb\8520111\Program\SERVIC~1.EXE[1760] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00FB1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\PROGRA~1\SECURI~1\Av_Fw\backweb\8520111\Program\SERVIC~1.EXE[1760] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00FB2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\Explorer.EXE[1828] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 02081FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\Explorer.EXE[1828] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 02082180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\Explorer.EXE[1828] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 00C5000A
.text C:\WINDOWS\Explorer.EXE[1828] WS2_32.dll!connect 719F4A07 5 Bytes JMP 00C4000A
.text C:\WINDOWS\Explorer.EXE[1828] WS2_32.dll!send 719F4C27 5 Bytes JMP 00C6000A
.text C:\Documents and Settings\HP_Propriétaire\Bureau\pdf bleu\bypass.exe[1952] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00E11FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Documents and Settings\HP_Propriétaire\Bureau\pdf bleu\bypass.exe[1952] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00E12180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[1968] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00F01FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe[1968] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00F02180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\hphmon06.exe[1980] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 011B1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\hphmon06.exe[1980] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 011B2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 01771FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\iTunes\iTunesHelper.exe[1992] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 01772180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\ps2.exe[2000] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 01051FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\ps2.exe[2000] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 01052180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\System32\alg.exe[2028] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00F31FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\System32\alg.exe[2028] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00F32180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Securitoo\Av_Fw\backweb\8520111\Program\fspex.exe[2068] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 02381FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Securitoo\Av_Fw\backweb\8520111\Program\fspex.exe[2068] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 02382180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe[2368] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 05EB1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe[2368] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 05EB2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\svchost.exe[2756] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00F21FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\svchost.exe[2756] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00F22180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\wdfmgr.exe[2872] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 009A1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\system32\wdfmgr.exe[2872] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 009A2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\wanmpsvc.exe[2980] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00DA1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\WINDOWS\wanmpsvc.exe[2980] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00DA2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe[3124] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 02911FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe[3124] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 02912180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE[3376] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 01921FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE[3376] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 01922180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Securitoo\Av_Fw\FSGUI\fsguiexe.exe[3396] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00CE1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Securitoo\Av_Fw\FSGUI\fsguiexe.exe[3396] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00CE2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[3900] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 01161FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\iPod\bin\iPodService.exe[3900] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 01162180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3956] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00D31FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe[3956] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00D32180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdfwd.exe[4000] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 011D1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdfwd.exe[4000] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 011D2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\a-squared Free\a2free.exe[4092] kernel32.dll!LoadLibraryExW 7C801AF5 7 Bytes JMP 00FD1FE0 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
.text C:\Program Files\a-squared Free\a2free.exe[4092] kernel32.dll!CreateThread + 1A 7C8106E1 4 Bytes [ C3, F4, C3, 83 ]
.text C:\Program Files\a-squared Free\a2free.exe[4092] kernel32.dll!CreateProcessInternalW 7C81979C 5 Bytes JMP 00FD2180 C:\Program Files\Securitoo\Av_Fw\FWES\Program\fsdc.dll (F-Secure Dial-up Control for Windows NT/F-Secure Corporation)
---- User IAT/EAT - GMER 1.0.14 ----
IAT C:\WINDOWS\system32\services.exe[628] @ C:\WINDOWS\system32\services.exe [ntdll.dll!NtQueryDirectoryFile] 00FE503C
IAT C:\WINDOWS\system32\services.exe[628] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00FE503C
IAT C:\WINDOWS\system32\services.exe[628] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00FE4F88
IAT C:\WINDOWS\system32\services.exe[628] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00FE4F23
IAT C:\WINDOWS\system32\services.exe[628] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00FE4EF1
IAT C:\WINDOWS\system32\services.exe[628] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00FE55AA
IAT C:\WINDOWS\system32\services.exe[628] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00FE503C
IAT C:\WINDOWS\system32\services.exe[628] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 00FE55AA
IAT C:\WINDOWS\system32\services.exe[628] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 00FE52F5
IAT C:\WINDOWS\system32\services.exe[628] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00FE52F5
IAT C:\WINDOWS\system32\services.exe[628] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00FE55AA
IAT C:\WINDOWS\system32\lsass.exe[640] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00DF503C
IAT C:\WINDOWS\system32\lsass.exe[640] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00DF4F88
IAT C:\WINDOWS\system32\lsass.exe[640] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00DF4F23
IAT C:\WINDOWS\system32\lsass.exe[640] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00DF4EF1
IAT C:\WINDOWS\system32\lsass.exe[640] @ C:\WINDOWS\system32\LSASRV.dll [ntdll.dll!LdrLoadDll] 00DF4F88
IAT C:\WINDOWS\system32\lsass.exe[640] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00DF503C
IAT C:\WINDOWS\system32\lsass.exe[640] @ C:\WINDOWS\system32\SAMSRV.dll [ntdll.dll!LdrLoadDll] 00DF4F88
IAT C:\WINDOWS\system32\lsass.exe[640] @ C:\WINDOWS\system32\SAMSRV.dll [ntdll.dll!LdrGetProcedureAddress] 00DF4F23
IAT C:\WINDOWS\system32\lsass.exe[640] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00DF52F5
IAT C:\WINDOWS\system32\lsass.exe[640] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00DF55AA
IAT C:\WINDOWS\system32\lsass.exe[640] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00DF55AA
IAT C:\WINDOWS\system32\lsass.exe[640] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00DF52F5
IAT C:\WINDOWS\system32\lsass.exe[640] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00DF55AA
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[708] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 0013503C
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[708] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00134F88
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[708] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00134F23
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[708] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00134EF1
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[708] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[708] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[708] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 001352F5
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[708] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 001352F5
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[708] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe[708] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 0013503C
IAT C:\Program Files\Securitoo\Av_Fw\Anti-Virus\fsgk32st.exe[776] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 0013503C
IAT C:\Program Files\Securitoo\Av_Fw\Anti-Virus\fsgk32st.exe[776] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00134F88
IAT C:\Program Files\Securitoo\Av_Fw\Anti-Virus\fsgk32st.exe[776] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00134F23
IAT C:\Program Files\Securitoo\Av_Fw\Anti-Virus\fsgk32st.exe[776] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00134EF1
IAT C:\Program Files\Securitoo\Av_Fw\Anti-Virus\fsgk32st.exe[776] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\Securitoo\Av_Fw\Anti-Virus\fsgk32st.exe[776] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 0013503C
IAT C:\Program Files\Securitoo\Av_Fw\Anti-Virus\fsgk32st.exe[776] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\Securitoo\Av_Fw\Anti-Virus\fsgk32st.exe[776] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 001352F5
IAT C:\Program Files\Securitoo\Av_Fw\Anti-Virus\fsgk32st.exe[776] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 001352F5
IAT C:\Program Files\Securitoo\Av_Fw\Anti-Virus\fsgk32st.exe[776] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\Mozilla Firefox\firefox.exe[832] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 0013503C
IAT C:\Program Files\Mozilla Firefox\firefox.exe[832] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00134F88
IAT C:\Program Files\Mozilla Firefox\firefox.exe[832] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00134F23
IAT C:\Program Files\Mozilla Firefox\firefox.exe[832] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00134EF1
IAT C:\Program Files\Mozilla Firefox\firefox.exe[832] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 0013503C
IAT C:\Program Files\Mozilla Firefox\firefox.exe[832] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\Mozilla Firefox\firefox.exe[832] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 001352F5
IAT C:\Program Files\Mozilla Firefox\firefox.exe[832] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\Mozilla Firefox\firefox.exe[832] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 001352F5
IAT C:\Program Files\Mozilla Firefox\firefox.exe[832] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\WINDOWS\system32\svchost.exe[836] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 010D4EF1
IAT C:\Program Files\Genie-Soft\GBALite8LaCie\GBMAgent.exe[884] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 0013503C
IAT C:\Program Files\Genie-Soft\GBALite8LaCie\GBMAgent.exe[884] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00134F88
IAT C:\Program Files\Genie-Soft\GBALite8LaCie\GBMAgent.exe[884] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00134F23
IAT C:\Program Files\Genie-Soft\GBALite8LaCie\GBMAgent.exe[884] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00134EF1
IAT C:\Program Files\Genie-Soft\GBALite8LaCie\GBMAgent.exe[884] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\Genie-Soft\GBALite8LaCie\GBMAgent.exe[884] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\Genie-Soft\GBALite8LaCie\GBMAgent.exe[884] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 001352F5
IAT C:\Program Files\Genie-Soft\GBALite8LaCie\GBMAgent.exe[884] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 001352F5
IAT C:\Program Files\Genie-Soft\GBALite8LaCie\GBMAgent.exe[884] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\Genie-Soft\GBALite8LaCie\GBMAgent.exe[884] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 0013503C
IAT C:\WINDOWS\system32\svchost.exe[928] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00FD503C
IAT C:\WINDOWS\system32\svchost.exe[928] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00FD4F88
IAT C:\WINDOWS\system32\svchost.exe[928] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00FD4F23
IAT C:\WINDOWS\system32\svchost.exe[928] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00FD4EF1
IAT C:\WINDOWS\system32\svchost.exe[928] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00FD52F5
IAT C:\WINDOWS\system32\svchost.exe[928] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00FD55AA
IAT C:\WINDOWS\system32\svchost.exe[928] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00FD55AA
IAT C:\WINDOWS\system32\svchost.exe[928] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00FD52F5
IAT C:\WINDOWS\system32\svchost.exe[928] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00FD55AA
IAT C:\WINDOWS\system32\svchost.exe[928] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00FD503C
IAT C:\WINDOWS\system32\ctfmon.exe[980] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 0008503C
IAT C:\WINDOWS\system32\ctfmon.exe[980] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00084F88
IAT C:\WINDOWS\system32\ctfmon.exe[980] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00084F23
IAT C:\WINDOWS\system32\ctfmon.exe[980] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00084EF1
IAT C:\WINDOWS\system32\ctfmon.exe[980] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 000852F5
IAT C:\WINDOWS\system32\ctfmon.exe[980] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 000855AA
IAT C:\WINDOWS\system32\ctfmon.exe[980] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 000855AA
IAT C:\WINDOWS\system32\ctfmon.exe[980] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 000852F5
IAT C:\WINDOWS\system32\ctfmon.exe[980] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 000855AA
IAT C:\WINDOWS\system32\ctfmon.exe[980] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 0008503C
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1000] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 00D8503C
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1000] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00D84F88
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1000] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00D84F23
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1000] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00D84EF1
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1000] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 00D855AA
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1000] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00D852F5
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1000] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 00D855AA
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1000] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00D852F5
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1000] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 00D855AA
IAT C:\Program Files\Windows Defender\MsMpEng.exe[1000] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 00D8503C
IAT C:\WINDOWS\System32\svchost.exe[1040] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 019A503C
IAT C:\WINDOWS\System32\svchost.exe[1040] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 019A4F88
IAT C:\WINDOWS\System32\svchost.exe[1040] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 019A4F23
IAT C:\WINDOWS\System32\svchost.exe[1040] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 019A4EF1
IAT C:\WINDOWS\System32\svchost.exe[1040] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 019A52F5
IAT C:\WINDOWS\System32\svchost.exe[1040] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 019A55AA
IAT C:\WINDOWS\System32\svchost.exe[1040] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TranslateMessage] 019A55AA
IAT C:\WINDOWS\System32\svchost.exe[1040] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 019A52F5
IAT C:\WINDOWS\System32\svchost.exe[1040] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 019A55AA
IAT C:\WINDOWS\System32\svchost.exe[1040] @ C:\WINDOWS\System32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 019A503C
IAT C:\Program Files\a-squared Free\a2service.exe[1580] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 0013503C
IAT C:\Program Files\a-squared Free\a2service.exe[1580] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00134F88
IAT C:\Program Files\a-squared Free\a2service.exe[1580] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00134F23
IAT C:\Program Files\a-squared Free\a2service.exe[1580] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00134EF1
IAT C:\Program Files\a-squared Free\a2service.exe[1580] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 001352F5
IAT C:\Program Files\a-squared Free\a2service.exe[1580] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\a-squared Free\a2service.exe[1580] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\a-squared Free\a2service.exe[1580] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 001352F5
IAT C:\Program Files\a-squared Free\a2service.exe[1580] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\a-squared Free\a2service.exe[1580] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 0013503C
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe[1636] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 0013503C
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe[1636] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00134F88
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe[1636] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00134F23
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe[1636] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00134EF1
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe[1636] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe[1636] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 0013503C
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe[1636] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe[1636] @ C:\WINDOWS\system32\shell32.dll [USER32.dll!GetClipboardData] 001352F5
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe[1636] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 001352F5
IAT C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe[1636] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtQueryDirectoryFile] 0013503C
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrLoadDll] 00134F88
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] 00134F23
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateThread] 00134EF1
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6BFA9B5A] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TranslateMessage] 001355AA
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryW] [6BFA9AD3] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryExW] [6BFA9BE7] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!LoadLibraryA] [6BFA9A4C] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\WS2HELP.dll [ntdll.dll!NtQueryDirectoryFile] 0013503C
IAT C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe[1672] @ C:\WINDOWS\system32\shell32.dll [KERNEL32.dll!SetUnhandledExceptionFilter] [6BFA9C74] C:\Program Files\Fichiers communs\AOL\AOLDiag\tbdiag.dll (AOL Diagnostics/AOL LLC)
IAT C:\PROGRA~1\FICH