Nejdou zabíjet procesy Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
CZechBoY
Master Level 9.5
Master Level 9.5
Příspěvky: 8813
Registrován: srpen 08
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Nejdou zabíjet procesy

Příspěvekod CZechBoY » 10 kvě 2014 13:56

[Address] EAT @explorer.exe (GdipAddPathArc) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EC868)
[Address] EAT @explorer.exe (GdipAddPathArcI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EC7C8)
[Address] EAT @explorer.exe (GdipAddPathBezier) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371F400)
[Address] EAT @explorer.exe (GdipAddPathBezierI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371F31C)
[Address] EAT @explorer.exe (GdipAddPathBeziers) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371F258)
[Address] EAT @explorer.exe (GdipAddPathBeziersI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371F174)
[Address] EAT @explorer.exe (GdipAddPathClosedCurve) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371EAC4)
[Address] EAT @explorer.exe (GdipAddPathClosedCurve2) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371E90C)
[Address] EAT @explorer.exe (GdipAddPathClosedCurve2I) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371E824)
[Address] EAT @explorer.exe (GdipAddPathClosedCurveI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371E9E0)
[Address] EAT @explorer.exe (GdipAddPathCurve) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371F094)
[Address] EAT @explorer.exe (GdipAddPathCurve2) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371EE94)
[Address] EAT @explorer.exe (GdipAddPathCurve2I) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371ED74)
[Address] EAT @explorer.exe (GdipAddPathCurve3) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371EC90)
[Address] EAT @explorer.exe (GdipAddPathCurve3I) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371EB90)
[Address] EAT @explorer.exe (GdipAddPathCurveI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371EF78)
[Address] EAT @explorer.exe (GdipAddPathEllipse) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371E3FC)
[Address] EAT @explorer.exe (GdipAddPathEllipseI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371E378)
[Address] EAT @explorer.exe (GdipAddPathLine) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EB964)
[Address] EAT @explorer.exe (GdipAddPathLine2) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371F61C)
[Address] EAT @explorer.exe (GdipAddPathLine2I) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371F538)
[Address] EAT @explorer.exe (GdipAddPathLineI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EB8E0)
[Address] EAT @explorer.exe (GdipAddPathPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371DF7C)
[Address] EAT @explorer.exe (GdipAddPathPie) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371E280)
[Address] EAT @explorer.exe (GdipAddPathPieI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371E1E0)
[Address] EAT @explorer.exe (GdipAddPathPolygon) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371E11C)
[Address] EAT @explorer.exe (GdipAddPathPolygonI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371E038)
[Address] EAT @explorer.exe (GdipAddPathRectangle) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371E730)
[Address] EAT @explorer.exe (GdipAddPathRectangleI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371E6AC)
[Address] EAT @explorer.exe (GdipAddPathRectangles) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371E5E8)
[Address] EAT @explorer.exe (GdipAddPathRectanglesI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371E4E8)
[Address] EAT @explorer.exe (GdipAddPathString) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371DDBC)
[Address] EAT @explorer.exe (GdipAddPathStringI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371DCD4)
[Address] EAT @explorer.exe (GdipAlloc) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36A9ADC)
[Address] EAT @explorer.exe (GdipBeginContainer) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370B1C4)
[Address] EAT @explorer.exe (GdipBeginContainer2) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370B100)
[Address] EAT @explorer.exe (GdipBeginContainerI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370B000)
[Address] EAT @explorer.exe (GdipBitmapApplyEffect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712874)
[Address] EAT @explorer.exe (GdipBitmapConvertFormat) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712B20)
[Address] EAT @explorer.exe (GdipBitmapCreateApplyEffect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371295C)
[Address] EAT @explorer.exe (GdipBitmapGetHistogram) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371278C)
[Address] EAT @explorer.exe (GdipBitmapGetHistogramSize) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712740)
[Address] EAT @explorer.exe (GdipBitmapGetPixel) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712E18)
[Address] EAT @explorer.exe (GdipBitmapLockBits) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36AC490)
[Address] EAT @explorer.exe (GdipBitmapSetPixel) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C31E0)
[Address] EAT @explorer.exe (GdipBitmapSetResolution) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C4880)
[Address] EAT @explorer.exe (GdipBitmapUnlockBits) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36AC5C8)
[Address] EAT @explorer.exe (GdipClearPathMarkers) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371F848)
[Address] EAT @explorer.exe (GdipCloneBitmapArea) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712F04)
[Address] EAT @explorer.exe (GdipCloneBitmapAreaI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F12D8)
[Address] EAT @explorer.exe (GdipCloneBrush) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371A32C)
[Address] EAT @explorer.exe (GdipCloneCustomLineCap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3715450)
[Address] EAT @explorer.exe (GdipCloneFont) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370996C)
[Address] EAT @explorer.exe (GdipCloneFontFamily) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709C18)
[Address] EAT @explorer.exe (GdipCloneImage) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C70D8)
[Address] EAT @explorer.exe (GdipCloneImageAttributes) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712538)
[Address] EAT @explorer.exe (GdipCloneMatrix) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EB360)
[Address] EAT @explorer.exe (GdipClonePath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3720184)
[Address] EAT @explorer.exe (GdipClonePen) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717048)
[Address] EAT @explorer.exe (GdipCloneRegion) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371B8FC)
[Address] EAT @explorer.exe (GdipCloneStringFormat) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708CF0)
[Address] EAT @explorer.exe (GdipClosePathFigure) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371FA28)
[Address] EAT @explorer.exe (GdipClosePathFigures) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371F988)
[Address] EAT @explorer.exe (GdipCombineRegionPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371B538)
[Address] EAT @explorer.exe (GdipCombineRegionRect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371B6F4)[Address] EAT @explorer.exe (GdipCombineRegionRectI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371B654)
[Address] EAT @explorer.exe (GdipCombineRegionRegion) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C88A4)
[Address] EAT @explorer.exe (GdipComment) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709878)
[Address] EAT @explorer.exe (GdipConvertToEmfPlus) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37080FC)
[Address] EAT @explorer.exe (GdipConvertToEmfPlusToFile) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3707FFC)
[Address] EAT @explorer.exe (GdipConvertToEmfPlusToStream) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3707EFC)
[Address] EAT @explorer.exe (GdipCreateAdjustableArrowCap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714B88)
[Address] EAT @explorer.exe (GdipCreateBitmapFromDirectDrawSurface) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37130A4)
[Address] EAT @explorer.exe (GdipCreateBitmapFromFile) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C06FC)
[Address] EAT @explorer.exe (GdipCreateBitmapFromFileICM) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3713330)
[Address] EAT @explorer.exe (GdipCreateBitmapFromGdiDib) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BB994)
[Address] EAT @explorer.exe (GdipCreateBitmapFromGraphics) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37131D4)
[Address] EAT @explorer.exe (GdipCreateBitmapFromHBITMAP) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36A2F28)
[Address] EAT @explorer.exe (GdipCreateBitmapFromHICON) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C7B2C)
[Address] EAT @explorer.exe (GdipCreateBitmapFromResource) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371300C)
[Address] EAT @explorer.exe (GdipCreateBitmapFromScan0) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B84A4)
[Address] EAT @explorer.exe (GdipCreateBitmapFromStream) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EFF40)
[Address] EAT @explorer.exe (GdipCreateBitmapFromStreamICM) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3713480)
[Address] EAT @explorer.exe (GdipCreateCachedBitmap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F2F6C)
[Address] EAT @explorer.exe (GdipCreateCustomLineCap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371551C)
[Address] EAT @explorer.exe (GdipCreateEffect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712DB0)
[Address] EAT @explorer.exe (GdipCreateFont) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C97BC)
[Address] EAT @explorer.exe (GdipCreateFontFamilyFromName) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C8DD4)
[Address] EAT @explorer.exe (GdipCreateFontFromDC) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709520)
[Address] EAT @explorer.exe (GdipCreateFontFromLogfontA) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709408)
[Address] EAT @explorer.exe (GdipCreateFontFromLogfontW) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C9380)
[Address] EAT @explorer.exe (GdipCreateFromHDC) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36AD848)
[Address] EAT @explorer.exe (GdipCreateFromHDC2) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371196C)
[Address] EAT @explorer.exe (GdipCreateFromHWND) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37118CC)
[Address] EAT @explorer.exe (GdipCreateFromHWNDICM) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371182C)
[Address] EAT @explorer.exe (GdipCreateHBITMAPFromBitmap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B3830)
[Address] EAT @explorer.exe (GdipCreateHICONFromBitmap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C779C)
[Address] EAT @explorer.exe (GdipCreateHalftonePalette) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C9ED8)
[Address] EAT @explorer.exe (GdipCreateHatchBrush) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371A198)
[Address] EAT @explorer.exe (GdipCreateImageAttributes) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C6D10)
[Address] EAT @explorer.exe (GdipCreateLineBrush) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371984C)
[Address] EAT @explorer.exe (GdipCreateLineBrushFromRect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F2150)
[Address] EAT @explorer.exe (GdipCreateLineBrushFromRectI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F2044)
[Address] EAT @explorer.exe (GdipCreateLineBrushFromRectWithAngle) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371961C)
[Address] EAT @explorer.exe (GdipCreateLineBrushFromRectWithAngleI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719514)
[Address] EAT @explorer.exe (GdipCreateLineBrushI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719738)
[Address] EAT @explorer.exe (GdipCreateMatrix) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B74C8)
[Address] EAT @explorer.exe (GdipCreateMatrix2) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EB244)
[Address] EAT @explorer.exe (GdipCreateMatrix3) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371C3C0)
[Address] EAT @explorer.exe (GdipCreateMatrix3I) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371C274)
[Address] EAT @explorer.exe (GdipCreateMetafileFromEmf) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370AB18)
[Address] EAT @explorer.exe (GdipCreateMetafileFromFile) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370AA30)
[Address] EAT @explorer.exe (GdipCreateMetafileFromStream) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370A854)
[Address] EAT @explorer.exe (GdipCreateMetafileFromWmf) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370AC0C)
[Address] EAT @explorer.exe (GdipCreateMetafileFromWmfFile) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370A93C)
[Address] EAT @explorer.exe (GdipCreatePath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BF200)
[Address] EAT @explorer.exe (GdipCreatePath2) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37203C4)
[Address] EAT @explorer.exe (GdipCreatePath2I) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC372023C)
[Address] EAT @explorer.exe (GdipCreatePathGradient) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718778)
[Address] EAT @explorer.exe (GdipCreatePathGradientFromPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718598)
[Address] EAT @explorer.exe (GdipCreatePathGradientI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371864C)
[Address] EAT @explorer.exe (GdipCreatePathIter) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371CEE0)
[Address] EAT @explorer.exe (GdipCreatePen1) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BA7E8)
[Address] EAT @explorer.exe (GdipCreatePen2) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B7D40)
[Address] EAT @explorer.exe (GdipCreateRegion) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C8040)
[Address] EAT @explorer.exe (GdipCreateRegionHrgn) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371BA00)
[Address] EAT @explorer.exe (GdipCreateRegionPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371BB94)
[Address] EAT @explorer.exe (GdipCreateRegionRect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36ED9CC)
[Address] EAT @explorer.exe (GdipCreateRegionRectI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36ED918)
[Address] EAT @explorer.exe (GdipCreateRegionRgnData) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371BAC8)
[Address] EAT @explorer.exe (GdipCreateSolidFill) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B5630)
[Address] EAT @explorer.exe (GdipCreateStreamOnFile) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36DAB24)
[Address] EAT @explorer.exe (GdipCreateStringFormat) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708EA0)
[Address] EAT @explorer.exe (GdipCreateTexture) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C2A40)
[Address] EAT @explorer.exe (GdipCreateTexture2) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719EC4)
[Address] EAT @explorer.exe (GdipCreateTexture2I) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719C40)
[Address] EAT @explorer.exe (GdipCreateTextureIA) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719D10)
[Address] EAT @explorer.exe (GdipCreateTextureIAI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719BF0)
[Address] EAT @explorer.exe (GdipDeleteBrush) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B5170)
[Address] EAT @explorer.exe (GdipDeleteCachedBitmap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C3498)
[Address] EAT @explorer.exe (GdipDeleteCustomLineCap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3715308)
[Address] EAT @explorer.exe (GdipDeleteEffect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712D60)
[Address] EAT @explorer.exe (GdipDeleteFont) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B834C)
[Address] EAT @explorer.exe (GdipDeleteFontFamily) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709CD0)
[Address] EAT @explorer.exe (GdipDeleteGraphics) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36AD378)
[Address] EAT @explorer.exe (GdipDeleteMatrix) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B73FC)
[Address] EAT @explorer.exe (GdipDeletePath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BF2E0)
[Address] EAT @explorer.exe (GdipDeletePathIter) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371CE4C)
[Address] EAT @explorer.exe (GdipDeletePen) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B521C)
[Address] EAT @explorer.exe (GdipDeletePrivateFontCollection) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370924C)
[Address] EAT @explorer.exe (GdipDeleteRegion) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B76B8)
[Address] EAT @explorer.exe (GdipDeleteStringFormat) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708C7C)
[Address] EAT @explorer.exe (GdipDisposeImage) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36A1CE0)
[Address] EAT @explorer.exe (GdipDisposeImageAttributes) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C6B70)
[Address] EAT @explorer.exe (GdipDrawArc) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371040C)
[Address] EAT @explorer.exe (GdipDrawArcI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3710360)
[Address] EAT @explorer.exe (GdipDrawBezier) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3710208)
[Address] EAT @explorer.exe (GdipDrawBezierI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3710114)
[Address] EAT @explorer.exe (GdipDrawBeziers) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370FFF8)
[Address] EAT @explorer.exe (GdipDrawBeziersI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370FEDC)
[Address] EAT @explorer.exe (GdipDrawCachedBitmap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F0EF0)
[Address] EAT @explorer.exe (GdipDrawClosedCurve) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370F140)
[Address] EAT @explorer.exe (GdipDrawClosedCurve2) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370EF38)
[Address] EAT @explorer.exe (GdipDrawClosedCurve2I) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370EE44)
[Address] EAT @explorer.exe (GdipDrawClosedCurveI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370F05C)
[Address] EAT @explorer.exe (GdipDrawCurve) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370F7B4)
[Address] EAT @explorer.exe (GdipDrawCurve2) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370F59C)
[Address] EAT @explorer.exe (GdipDrawCurve2I) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370F4A8)
[Address] EAT @explorer.exe (GdipDrawCurve3) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370F374)
[Address] EAT @explorer.exe (GdipDrawCurve3I) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370F268)
[Address] EAT @explorer.exe (GdipDrawCurveI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370F6D0)
[Address] EAT @explorer.exe (GdipDrawDriverString) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370D9A8)
[Address] EAT @explorer.exe (GdipDrawEllipse) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370FB64)
[Address] EAT @explorer.exe (GdipDrawEllipseI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370FAD4)
PHP, Nette, MySQL, C#, TypeScript, Python
IntelliJ Idea, Docker, Opera browser, Linux Mint
iPhone XS
Raspberry PI 3 (KODI, Raspbian)
XBox One S, PS 4, nVidia GeForce NOW

Reklama
Uživatelský avatar
CZechBoY
Master Level 9.5
Master Level 9.5
Příspěvky: 8813
Registrován: srpen 08
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Nejdou zabíjet procesy

Příspěvekod CZechBoY » 10 kvě 2014 13:56

[Address] EAT @explorer.exe (GdipDrawImage) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C2DF0)
[Address] EAT @explorer.exe (GdipDrawImageFX) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370D004)
[Address] EAT @explorer.exe (GdipDrawImageI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C2D6C)
[Address] EAT @explorer.exe (GdipDrawImagePointRect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36ED77C)
[Address] EAT @explorer.exe (GdipDrawImagePointRectI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36ED6B8)
[Address] EAT @explorer.exe (GdipDrawImagePoints) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370D658)
[Address] EAT @explorer.exe (GdipDrawImagePointsI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370D53C)
[Address] EAT @explorer.exe (GdipDrawImagePointsRect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370D2CC)
[Address] EAT @explorer.exe (GdipDrawImagePointsRectI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370D134)
[Address] EAT @explorer.exe (GdipDrawImageRect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B2664)
[Address] EAT @explorer.exe (GdipDrawImageRectI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B25C4)
[Address] EAT @explorer.exe (GdipDrawImageRectRect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EEFC4)
[Address] EAT @explorer.exe (GdipDrawImageRectRectI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EEE90)
[Address] EAT @explorer.exe (GdipDrawLine) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37105D8)
[Address] EAT @explorer.exe (GdipDrawLineI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3710548)
[Address] EAT @explorer.exe (GdipDrawLines) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BCA40)
[Address] EAT @explorer.exe (GdipDrawLinesI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BC958)
[Address] EAT @explorer.exe (GdipDrawPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EAFA0)
[Address] EAT @explorer.exe (GdipDrawPie) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370F998)
[Address] EAT @explorer.exe (GdipDrawPieI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370F8EC)
[Address] EAT @explorer.exe (GdipDrawPolygon) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36D27D0)
[Address] EAT @explorer.exe (GdipDrawPolygonI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36D26E0)
[Address] EAT @explorer.exe (GdipDrawRectangle) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BCD30)
[Address] EAT @explorer.exe (GdipDrawRectangleI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BCC90)
[Address] EAT @explorer.exe (GdipDrawRectangles) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370FDC0)
[Address] EAT @explorer.exe (GdipDrawRectanglesI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370FC88)
[Address] EAT @explorer.exe (GdipDrawString) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370E018)
[Address] EAT @explorer.exe (GdipEmfToWmfBits) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36D6A28)
[Address] EAT @explorer.exe (GdipEndContainer) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370AF58)
[Address] EAT @explorer.exe (GdipEnumerateMetafileDestPoint) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370CE6C)
[Address] EAT @explorer.exe (GdipEnumerateMetafileDestPointI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370CDD0)
[Address] EAT @explorer.exe (GdipEnumerateMetafileDestPoints) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370C9D4)
[Address] EAT @explorer.exe (GdipEnumerateMetafileDestPointsI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370C894)
[Address] EAT @explorer.exe (GdipEnumerateMetafileDestRect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370CC38)
[Address] EAT @explorer.exe (GdipEnumerateMetafileDestRectI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370CB80)
[Address] EAT @explorer.exe (GdipEnumerateMetafileSrcRectDestPoint) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370C6D0)
[Address] EAT @explorer.exe (GdipEnumerateMetafileSrcRectDestPointI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370C5E0)
[Address] EAT @explorer.exe (GdipEnumerateMetafileSrcRectDestPoints) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370C15C)
[Address] EAT @explorer.exe (GdipEnumerateMetafileSrcRectDestPointsI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370BFD4)
[Address] EAT @explorer.exe (GdipEnumerateMetafileSrcRectDestRect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370C41C)
[Address] EAT @explorer.exe (GdipEnumerateMetafileSrcRectDestRectI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370C328)
[Address] EAT @explorer.exe (GdipFillClosedCurve) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370E524)
[Address] EAT @explorer.exe (GdipFillClosedCurve2) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370E310)
[Address] EAT @explorer.exe (GdipFillClosedCurve2I) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370E210)
[Address] EAT @explorer.exe (GdipFillClosedCurveI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370E440)
[Address] EAT @explorer.exe (GdipFillEllipse) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BF768)
[Address] EAT @explorer.exe (GdipFillEllipseI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370E990)
[Address] EAT @explorer.exe (GdipFillPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370E654)
[Address] EAT @explorer.exe (GdipFillPie) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370E850)
[Address] EAT @explorer.exe (GdipFillPieI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370E79C)
[Address] EAT @explorer.exe (GdipFillPolygon) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36D29AC)
[Address] EAT @explorer.exe (GdipFillPolygon2) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370EB04)
[Address] EAT @explorer.exe (GdipFillPolygon2I) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370EA20)
[Address] EAT @explorer.exe (GdipFillPolygonI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36D28BC)
[Address] EAT @explorer.exe (GdipFillRectangle) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B5870)
[Address] EAT @explorer.exe (GdipFillRectangleI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B57DC)
[Address] EAT @explorer.exe (GdipFillRectangles) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370ED28)
[Address] EAT @explorer.exe (GdipFillRectanglesI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370EC28)
[Address] EAT @explorer.exe (GdipFillRegion) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36ED354)
[Address] EAT @explorer.exe (GdipFindFirstImageItem) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3713730)
[Address] EAT @explorer.exe (GdipFindNextImageItem) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3713680)
[Address] EAT @explorer.exe (GdipFlattenPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EAEC4)
[Address] EAT @explorer.exe (GdipFlush) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3711764)
[Address] EAT @explorer.exe (GdipFree) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36A9A74)
[Address] EAT @explorer.exe (GdipGetAdjustableArrowCapFillState) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37145B0)
[Address] EAT @explorer.exe (GdipGetAdjustableArrowCapHeight) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714A10)
[Address] EAT @explorer.exe (GdipGetAdjustableArrowCapMiddleInset) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714720)
[Address] EAT @explorer.exe (GdipGetAdjustableArrowCapWidth) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714898)
[Address] EAT @explorer.exe (GdipGetAllPropertyItems) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C11D8)
[Address] EAT @explorer.exe (GdipGetBrushType) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371A27C)
[Address] EAT @explorer.exe (GdipGetCellAscent) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709708)
[Address] EAT @explorer.exe (GdipGetCellDescent) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709644)
[Address] EAT @explorer.exe (GdipGetClip) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C8424)
[Address] EAT @explorer.exe (GdipGetClipBounds) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370B938)
[Address] EAT @explorer.exe (GdipGetClipBoundsI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B7B04)
[Address] EAT @explorer.exe (GdipGetCompositingMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36ED0E0)
[Address] EAT @explorer.exe (GdipGetCompositingQuality) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3711478)
[Address] EAT @explorer.exe (GdipGetCustomLineCapBaseCap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714EF4)
[Address] EAT @explorer.exe (GdipGetCustomLineCapBaseInset) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714DBC)
[Address] EAT @explorer.exe (GdipGetCustomLineCapStrokeCaps) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3715198)
[Address] EAT @explorer.exe (GdipGetCustomLineCapStrokeJoin) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3715058)
[Address] EAT @explorer.exe (GdipGetCustomLineCapType) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371539C)
[Address] EAT @explorer.exe (GdipGetCustomLineCapWidthScale) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714C84)
[Address] EAT @explorer.exe (GdipGetDC) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36D35E8)
[Address] EAT @explorer.exe (GdipGetDpiX) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3710A68)
[Address] EAT @explorer.exe (GdipGetDpiY) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C8AD8)
[Address] EAT @explorer.exe (GdipGetEffectParameterSize) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712C8C)
[Address] EAT @explorer.exe (GdipGetEffectParameters) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712C18)
[Address] EAT @explorer.exe (GdipGetEmHeight) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C9A70)
[Address] EAT @explorer.exe (GdipGetEncoderParameterList) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371419C)
[Address] EAT @explorer.exe (GdipGetEncoderParameterListSize) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714260)
[Address] EAT @explorer.exe (GdipGetFamily) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C8C70)
[Address] EAT @explorer.exe (GdipGetFamilyName) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C9984)
[Address] EAT @explorer.exe (GdipGetFontCollectionFamilyCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709178)
[Address] EAT @explorer.exe (GdipGetFontCollectionFamilyList) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37090BC)
[Address] EAT @explorer.exe (GdipGetFontHeight) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C9660)
[Address] EAT @explorer.exe (GdipGetFontHeightGivenDPI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709A64)
[Address] EAT @explorer.exe (GdipGetFontSize) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C8CF0)
[Address] EAT @explorer.exe (GdipGetFontStyle) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C8B6C)
[Address] EAT @explorer.exe (GdipGetFontUnit) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C8BF0)
[Address] EAT @explorer.exe (GdipGetGenericFontFamilyMonospace) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709DC4)
[Address] EAT @explorer.exe (GdipGetGenericFontFamilySansSerif) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709EAC)
[Address] EAT @explorer.exe (GdipGetGenericFontFamilySerif) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709E38)
[Address] EAT @explorer.exe (GdipGetHatchBackgroundColor) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371A030)
[Address] EAT @explorer.exe (GdipGetHatchForegroundColor) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37184E4)
[Address] EAT @explorer.exe (GdipGetHatchStyle) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371A0E4)
[Address] EAT @explorer.exe (GdipGetHemfFromMetafile) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36D5A24)
[Address] EAT @explorer.exe (GdipGetImageAttributesAdjustedPalette) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3711A18)
[Address] EAT @explorer.exe (GdipGetImageBounds) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3713CEC)
[Address] EAT @explorer.exe (GdipGetImageDecoders) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36E9270)
[Address] EAT @explorer.exe (GdipGetImageDecodersSize) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36E9428)
[Address] EAT @explorer.exe (GdipGetImageDimension) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3713C28)
[Address] EAT @explorer.exe (GdipGetImageEncoders) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36A6798)
[Address] EAT @explorer.exe (GdipGetImageEncodersSize) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36A69D8)
[Address] EAT @explorer.exe (GdipGetImageFlags) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371396C)
[Address] EAT @explorer.exe (GdipGetImageGraphicsContext) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B9214)
[Address] EAT @explorer.exe (GdipGetImageHeight) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36AB680)
[Address] EAT @explorer.exe (GdipGetImageHorizontalResolution) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3713B3C)
[Address] EAT @explorer.exe (GdipGetImageItemData) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37135D0)
[Address] EAT @explorer.exe (GdipGetImagePalette) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F05B4)
[Address] EAT @explorer.exe (GdipGetImagePaletteSize) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F067C)
[Address] EAT @explorer.exe (GdipGetImagePixelFormat) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36AB588)
[Address] EAT @explorer.exe (GdipGetImageRawFormat) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C18F4)
[Address] EAT @explorer.exe (GdipGetImageThumbnail) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37137E0)
[Address] EAT @explorer.exe (GdipGetImageType) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C6EA0)
[Address] EAT @explorer.exe (GdipGetImageVerticalResolution) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3713A50)
[Address] EAT @explorer.exe (GdipGetImageWidth) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36AC344)
[Address] EAT @explorer.exe (GdipGetInterpolationMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3711108)
[Address] EAT @explorer.exe (GdipGetLineBlend) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37190C8)
[Address] EAT @explorer.exe (GdipGetLineBlendCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717A4C)
[Address] EAT @explorer.exe (GdipGetLineColors) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719360)
[Address] EAT @explorer.exe (GdipGetLineGammaCorrection) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719198)
[Address] EAT @explorer.exe (GdipGetLinePresetBlend) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718E88)
[Address] EAT @explorer.exe (GdipGetLinePresetBlendCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719004)
[Address] EAT @explorer.exe (GdipGetLineRect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717C48)
[Address] EAT @explorer.exe (GdipGetLineRectI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719280)
[Address] EAT @explorer.exe (GdipGetLineSpacing) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C9B34)
[Address] EAT @explorer.exe (GdipGetLineTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719AD0)
[Address] EAT @explorer.exe (GdipGetLineWrapMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718AA0)
[Address] EAT @explorer.exe (GdipGetLogFontA) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709B0C)
[Address] EAT @explorer.exe (GdipGetLogFontW) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C8EEC)
[Address] EAT @explorer.exe (GdipGetMatrixElements) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B75F0)
[Address] EAT @explorer.exe (GdipGetMetafileDownLevelRasterizationLimit) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709F20)
[Address] EAT @explorer.exe (GdipGetMetafileHeaderFromEmf) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370AE8C)
[Address] EAT @explorer.exe (GdipGetMetafileHeaderFromFile) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370AE34)
[Address] EAT @explorer.exe (GdipGetMetafileHeaderFromMetafile) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370AD14)
[Address] EAT @explorer.exe (GdipGetMetafileHeaderFromStream) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370ADC4)
[Address] EAT @explorer.exe (GdipGetMetafileHeaderFromWmf) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370AEE4)
[Address] EAT @explorer.exe (GdipGetNearestColor) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37106F8)
[Address] EAT @explorer.exe (GdipGetPageScale) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3710BD0)
[Address] EAT @explorer.exe (GdipGetPageUnit) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3710C84)
[Address] EAT @explorer.exe (GdipGetPathData) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371FB68)
[Address] EAT @explorer.exe (GdipGetPathFillMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371FC14)
[Address] EAT @explorer.exe (GdipGetPathGradientBlend) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371797C)
[Address] EAT @explorer.exe (GdipGetPathGradientBlendCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717A4C)
[Address] EAT @explorer.exe (GdipGetPathGradientCenterColor) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37184E4)
[Address] EAT @explorer.exe (GdipGetPathGradientCenterPoint) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718034)
[Address] EAT @explorer.exe (GdipGetPathGradientCenterPointI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717F98)
[Address] EAT @explorer.exe (GdipGetPathGradientFocusScales) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37171BC)
[Address] EAT @explorer.exe (GdipGetPathGradientGammaCorrection) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717B00)
[Address] EAT @explorer.exe (GdipGetPathGradientPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37180E0)
[Address] EAT @explorer.exe (GdipGetPathGradientPointCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717DB4)
[Address] EAT @explorer.exe (GdipGetPathGradientPresetBlend) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717764)
[Address] EAT @explorer.exe (GdipGetPathGradientPresetBlendCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719004)
[Address] EAT @explorer.exe (GdipGetPathGradientRect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717C48)
[Address] EAT @explorer.exe (GdipGetPathGradientRectI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719280)
[Address] EAT @explorer.exe (GdipGetPathGradientSurroundColorCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717CF8)
[Address] EAT @explorer.exe (GdipGetPathGradientSurroundColorsWithCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37182FC)
[Address] EAT @explorer.exe (GdipGetPathGradientTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719AD0)
[Address] EAT @explorer.exe (GdipGetPathGradientWrapMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718AA0)
[Address] EAT @explorer.exe (GdipGetPathLastPoint) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371F6E0)
[Address] EAT @explorer.exe (GdipGetPathPoints) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371FE14)
[Address] EAT @explorer.exe (GdipGetPathPointsI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371FCC8)
[Address] EAT @explorer.exe (GdipGetPathTypes) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371FF24)
[Address] EAT @explorer.exe (GdipGetPathWorldBounds) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371D680)
[Address] EAT @explorer.exe (GdipGetPathWorldBoundsI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371D4FC)
[Address] EAT @explorer.exe (GdipGetPenBrushFill) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3715D44)
[Address] EAT @explorer.exe (GdipGetPenColor) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BF640)
[Address] EAT @explorer.exe (GdipGetPenCompoundArray) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37156CC)
[Address] EAT @explorer.exe (GdipGetPenCompoundCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371586C)
[Address] EAT @explorer.exe (GdipGetPenCustomEndCap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371674C)
[Address] EAT @explorer.exe (GdipGetPenCustomStartCap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37168FC)
[Address] EAT @explorer.exe (GdipGetPenDashArray) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371591C)
[Address] EAT @explorer.exe (GdipGetPenDashCap197819) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3716B5C)
[Address] EAT @explorer.exe (GdipGetPenDashCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3715A94)
[Address] EAT @explorer.exe (GdipGetPenDashOffset) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3715BE4)
[Address] EAT @explorer.exe (GdipGetPenDashStyle) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3715C94)
[Address] EAT @explorer.exe (GdipGetPenEndCap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3716C10)
[Address] EAT @explorer.exe (GdipGetPenFillType) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BFB50)
[Address] EAT @explorer.exe (GdipGetPenLineJoin) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3716AAC)
[Address] EAT @explorer.exe (GdipGetPenMiterLimit) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37165F0)
[Address] EAT @explorer.exe (GdipGetPenMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3716498)
[Address] EAT @explorer.exe (GdipGetPenStartCap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3716CC0)
[Address] EAT @explorer.exe (GdipGetPenTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371624C)
[Address] EAT @explorer.exe (GdipGetPenUnit) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3716EE4)
[Address] EAT @explorer.exe (GdipGetPenWidth) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BF6E0)
[Address] EAT @explorer.exe (GdipGetPixelOffsetMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37113C4)
[Address] EAT @explorer.exe (GdipGetPointCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3720030)
[Address] EAT @explorer.exe (GdipGetPropertyCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3713F08)
[Address] EAT @explorer.exe (GdipGetPropertyIdList) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3713E6C)
[Address] EAT @explorer.exe (GdipGetPropertyItem) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C57EC)
[Address] EAT @explorer.exe (GdipGetPropertyItemSize) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C5760)
[Address] EAT @explorer.exe (GdipGetPropertySize) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BFEF0)
[Address] EAT @explorer.exe (GdipGetRegionBounds) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371B260)
[Address] EAT @explorer.exe (GdipGetRegionBoundsI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371B0C4)
[Address] EAT @explorer.exe (GdipGetRegionData) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371ABA8)
[Address] EAT @explorer.exe (GdipGetRegionDataSize) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371AC7C)
[Address] EAT @explorer.exe (GdipGetRegionHRgn) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C866C)
[Address] EAT @explorer.exe (GdipGetRegionScans) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371A4EC)
[Address] EAT @explorer.exe (GdipGetRegionScansCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371A60C)
[Address] EAT @explorer.exe (GdipGetRegionScansI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371A3EC)
[Address] EAT @explorer.exe (GdipGetRenderingOrigin) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37115D4)
[Address] EAT @explorer.exe (GdipGetSmoothingMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BAA70)
[Address] EAT @explorer.exe (GdipGetSolidFillColor) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719964)
[Address] EAT @explorer.exe (GdipGetStringFormatAlign) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708A30)
[Address] EAT @explorer.exe (GdipGetStringFormatDigitSubstitution) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708390)
[Address] EAT @explorer.exe (GdipGetStringFormatFlags) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708B58)
[Address] EAT @explorer.exe (GdipGetStringFormatHotkeyPrefix) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37087E0)
[Address] EAT @explorer.exe (GdipGetStringFormatLineAlign) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708908)
[Address] EAT @explorer.exe (GdipGetStringFormatMeasurableCharacterRangeCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370856C)
PHP, Nette, MySQL, C#, TypeScript, Python
IntelliJ Idea, Docker, Opera browser, Linux Mint
iPhone XS
Raspberry PI 3 (KODI, Raspbian)
XBox One S, PS 4, nVidia GeForce NOW

Uživatelský avatar
CZechBoY
Master Level 9.5
Master Level 9.5
Příspěvky: 8813
Registrován: srpen 08
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Nejdou zabíjet procesy

Příspěvekod CZechBoY » 10 kvě 2014 13:56

[Address] EAT @explorer.exe (GdipGetStringFormatTabStopCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708698)
[Address] EAT @explorer.exe (GdipGetStringFormatTabStops) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37085DC)
[Address] EAT @explorer.exe (GdipGetStringFormatTrimming) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708260)
[Address] EAT @explorer.exe (GdipGetTextContrast) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37111B0)
[Address] EAT @explorer.exe (GdipGetTextRenderingHint) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C8160)
[Address] EAT @explorer.exe (GdipGetTextureImage) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EDE20)
[Address] EAT @explorer.exe (GdipGetTextureTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719AD0)
[Address] EAT @explorer.exe (GdipGetTextureWrapMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EDCCC)
[Address] EAT @explorer.exe (GdipGetVisibleClipBounds) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370B7D0)
[Address] EAT @explorer.exe (GdipGetVisibleClipBoundsI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370B690)
[Address] EAT @explorer.exe (GdipGetWorldTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B780C)
[Address] EAT @explorer.exe (GdipGraphicsClear) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C19E8)
[Address] EAT @explorer.exe (GdipGraphicsSetAbort) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37125EC)
[Address] EAT @explorer.exe (GdipImageForceValidation) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C6F4C)
[Address] EAT @explorer.exe (GdipImageGetFrameCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F0478)
[Address] EAT @explorer.exe (GdipImageGetFrameDimensionsCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F0204)
[Address] EAT @explorer.exe (GdipImageGetFrameDimensionsList) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F02A4)
[Address] EAT @explorer.exe (GdipImageRotateFlip) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F3500)
[Address] EAT @explorer.exe (GdipImageSelectActiveFrame) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3713F94)
[Address] EAT @explorer.exe (GdipImageSetAbort) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712690)
[Address] EAT @explorer.exe (GdipInitializePalette) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712A30)
[Address] EAT @explorer.exe (GdipInvertMatrix) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371C100)
[Address] EAT @explorer.exe (GdipIsClipEmpty) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370B884)
[Address] EAT @explorer.exe (GdipIsEmptyRegion) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371AF40)
[Address] EAT @explorer.exe (GdipIsEqualRegion) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371AD48)
[Address] EAT @explorer.exe (GdipIsInfiniteRegion) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C8268)
[Address] EAT @explorer.exe (GdipIsMatrixEqual) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371BCA0)
[Address] EAT @explorer.exe (GdipIsMatrixIdentity) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B7760)
[Address] EAT @explorer.exe (GdipIsMatrixInvertible) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371BDC4)
[Address] EAT @explorer.exe (GdipIsOutlineVisiblePathPoint) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371D080)
[Address] EAT @explorer.exe (GdipIsOutlineVisiblePathPointI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371CFF8)
[Address] EAT @explorer.exe (GdipIsStyleAvailable) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37097B8)
[Address] EAT @explorer.exe (GdipIsVisibleClipEmpty) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370B5D4)
[Address] EAT @explorer.exe (GdipIsVisiblePathPoint) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371D344)
[Address] EAT @explorer.exe (GdipIsVisiblePathPointI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371D2C8)
[Address] EAT @explorer.exe (GdipIsVisiblePoint) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370B4F0)
[Address] EAT @explorer.exe (GdipIsVisiblePointI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370B480)
[Address] EAT @explorer.exe (GdipIsVisibleRect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370B37C)
[Address] EAT @explorer.exe (GdipIsVisibleRectI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370B2F0)
[Address] EAT @explorer.exe (GdipIsVisibleRegionPoint) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371AA08)
[Address] EAT @explorer.exe (GdipIsVisibleRegionPointI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371A98C)
[Address] EAT @explorer.exe (GdipIsVisibleRegionRect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371A7A8)
[Address] EAT @explorer.exe (GdipIsVisibleRegionRectI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371A70C)
[Address] EAT @explorer.exe (GdipLoadImageFromFile) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37144D4)
[Address] EAT @explorer.exe (GdipLoadImageFromFileICM) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714314)
[Address] EAT @explorer.exe (GdipLoadImageFromStream) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B9F24)
[Address] EAT @explorer.exe (GdipLoadImageFromStreamICM) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37143F4)
[Address] EAT @explorer.exe (GdipMeasureCharacterRanges) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370DC28)
[Address] EAT @explorer.exe (GdipMeasureDriverString) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370D7D0)
[Address] EAT @explorer.exe (GdipMeasureString) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370DDF0)
[Address] EAT @explorer.exe (GdipMultiplyLineTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717354)
[Address] EAT @explorer.exe (GdipMultiplyMatrix) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EA8BC)
[Address] EAT @explorer.exe (GdipMultiplyPathGradientTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717354)
[Address] EAT @explorer.exe (GdipMultiplyPenTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3716094)
[Address] EAT @explorer.exe (GdipMultiplyTextureTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717354)
[Address] EAT @explorer.exe (GdipMultiplyWorldTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3710F58)
[Address] EAT @explorer.exe (GdipNewInstalledFontCollection) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37093A0)
[Address] EAT @explorer.exe (GdipNewPrivateFontCollection) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37092EC)
[Address] EAT @explorer.exe (GdipPathIterCopyData) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371C4A8)
[Address] EAT @explorer.exe (GdipPathIterEnumerate) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371C598)
[Address] EAT @explorer.exe (GdipPathIterGetCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371C93C)
[Address] EAT @explorer.exe (GdipPathIterGetSubpathCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371C888)
[Address] EAT @explorer.exe (GdipPathIterHasCurve) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371C728)
[Address] EAT @explorer.exe (GdipPathIterIsValid) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371C7D4)
[Address] EAT @explorer.exe (GdipPathIterNextMarker) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371CAB4)
[Address] EAT @explorer.exe (GdipPathIterNextMarkerPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371C9F0)
[Address] EAT @explorer.exe (GdipPathIterNextPathType) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371CB98)
[Address] EAT @explorer.exe (GdipPathIterNextSubpath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371CD5C)
[Address] EAT @explorer.exe (GdipPathIterNextSubpathPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371CC84)
[Address] EAT @explorer.exe (GdipPathIterRewind) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371C680)
[Address] EAT @explorer.exe (GdipPlayMetafileRecord) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370BEF4)
[Address] EAT @explorer.exe (GdipPlayTSClientRecord) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37079F8)
[Address] EAT @explorer.exe (GdipPrivateAddFontFile) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3709020)
[Address] EAT @explorer.exe (GdipPrivateAddMemoryFont) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708F74)
[Address] EAT @explorer.exe (GdipRecordMetafile) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36E2A54)
[Address] EAT @explorer.exe (GdipRecordMetafileFileName) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370A510)
[Address] EAT @explorer.exe (GdipRecordMetafileFileNameI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370A40C)
[Address] EAT @explorer.exe (GdipRecordMetafileI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370A66C)
[Address] EAT @explorer.exe (GdipRecordMetafileStream) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370A2B0)
[Address] EAT @explorer.exe (GdipRecordMetafileStreamI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370A1AC)
[Address] EAT @explorer.exe (GdipReleaseDC) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36D3508)
[Address] EAT @explorer.exe (GdipRemovePropertyItem) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3713DE0)
[Address] EAT @explorer.exe (GdipResetClip) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36D2D60)
[Address] EAT @explorer.exe (GdipResetImageAttributes) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712358)
[Address] EAT @explorer.exe (GdipResetLineTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718914)
[Address] EAT @explorer.exe (GdipResetPageTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3710D38)
[Address] EAT @explorer.exe (GdipResetPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37200E0)
[Address] EAT @explorer.exe (GdipResetPathGradientTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718914)
[Address] EAT @explorer.exe (GdipResetPenTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3716198)
[Address] EAT @explorer.exe (GdipResetTextureTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718914)
[Address] EAT @explorer.exe (GdipResetWorldTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371106C)
[Address] EAT @explorer.exe (GdipRestoreGraphics) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C81E8)
[Address] EAT @explorer.exe (GdipReversePath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371F7A8)
[Address] EAT @explorer.exe (GdipRotateLineTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719A18)
[Address] EAT @explorer.exe (GdipRotateMatrix) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EB700)
[Address] EAT @explorer.exe (GdipRotatePathGradientTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719A18)
[Address] EAT @explorer.exe (GdipRotatePenTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3715E0C)
[Address] EAT @explorer.exe (GdipRotateTextureTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719A18)
[Address] EAT @explorer.exe (GdipRotateWorldTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3710DE0)
[Address] EAT @explorer.exe (GdipSaveAdd) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37140F8)
[Address] EAT @explorer.exe (GdipSaveAddImage) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714040)
[Address] EAT @explorer.exe (GdipSaveGraphics) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C7F9C)
[Address] EAT @explorer.exe (GdipSaveImageToFile) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36A5FD0)
[Address] EAT @explorer.exe (GdipSaveImageToStream) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BFC80)
[Address] EAT @explorer.exe (GdipScaleLineTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371728C)
[Address] EAT @explorer.exe (GdipScaleMatrix) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EA738)
[Address] EAT @explorer.exe (GdipScalePathGradientTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371728C)
[Address] EAT @explorer.exe (GdipScalePenTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3715EDC)
[Address] EAT @explorer.exe (GdipScaleTextureTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371728C)
[Address] EAT @explorer.exe (GdipScaleWorldTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3710E94)
[Address] EAT @explorer.exe (GdipSetAdjustableArrowCapFillState) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714660)
[Address] EAT @explorer.exe (GdipSetAdjustableArrowCapHeight) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714AC0)
[Address] EAT @explorer.exe (GdipSetAdjustableArrowCapMiddleInset) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37147D0)
[Address] EAT @explorer.exe (GdipSetAdjustableArrowCapWidth) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714948)
[Address] EAT @explorer.exe (GdipSetClipGraphics) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370BDEC)
[Address] EAT @explorer.exe (GdipSetClipHrgn) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370BB08)
[Address] EAT @explorer.exe (GdipSetClipPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370BCDC)
[Address] EAT @explorer.exe (GdipSetClipRect) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B69B0)
[Address] EAT @explorer.exe (GdipSetClipRectI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B6910)
[Address] EAT @explorer.exe (GdipSetClipRegion) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370BBD4)
[Address] EAT @explorer.exe (GdipSetCompositingMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C3358)
[Address] EAT @explorer.exe (GdipSetCompositingQuality) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371152C)
[Address] EAT @explorer.exe (GdipSetCustomLineCapBaseCap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714FA0)
[Address] EAT @explorer.exe (GdipSetCustomLineCapBaseInset) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714E5C)
[Address] EAT @explorer.exe (GdipSetCustomLineCapStrokeCaps) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3715250)
[Address] EAT @explorer.exe (GdipSetCustomLineCapStrokeJoin) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3715104)
[Address] EAT @explorer.exe (GdipSetCustomLineCapWidthScale) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3714D24)
[Address] EAT @explorer.exe (GdipSetEffectParameters) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712CEC)
[Address] EAT @explorer.exe (GdipSetEmpty) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371B7C4)
[Address] EAT @explorer.exe (GdipSetImageAttributesCachedBackground) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3711BC8)
[Address] EAT @explorer.exe (GdipSetImageAttributesColorKeys) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C7460)
[Address] EAT @explorer.exe (GdipSetImageAttributesColorMatrix) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712284)
[Address] EAT @explorer.exe (GdipSetImageAttributesGamma) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371205C)
[Address] EAT @explorer.exe (GdipSetImageAttributesNoOp) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3711F54)
[Address] EAT @explorer.exe (GdipSetImageAttributesOutputChannel) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3711E38)
[Address] EAT @explorer.exe (GdipSetImageAttributesOutputChannelColorProfile) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3711D74)
[Address] EAT @explorer.exe (GdipSetImageAttributesRemapTable) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3711C70)
[Address] EAT @explorer.exe (GdipSetImageAttributesThreshold) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712164)
[Address] EAT @explorer.exe (GdipSetImageAttributesToIdentity) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3712448)
[Address] EAT @explorer.exe (GdipSetImageAttributesWrapMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3711B10)
[Address] EAT @explorer.exe (GdipSetImagePalette) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37138AC)
[Address] EAT @explorer.exe (GdipSetInfinite) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371B860)
[Address] EAT @explorer.exe (GdipSetInterpolationMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F1170)
[Address] EAT @explorer.exe (GdipSetLineBlend) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F273C)
[Address] EAT @explorer.exe (GdipSetLineColors) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719454)
[Address] EAT @explorer.exe (GdipSetLineGammaCorrection) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3719214)
[Address] EAT @explorer.exe (GdipSetLineLinearBlend) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718C10)
[Address] EAT @explorer.exe (GdipSetLinePresetBlend) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718CD0)
[Address] EAT @explorer.exe (GdipSetLineSigmaBlend) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F2A58)
[Address] EAT @explorer.exe (GdipSetLineTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37189B4)
[Address] EAT @explorer.exe (GdipSetLineWrapMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718B50)
[Address] EAT @explorer.exe (GdipSetMatrixElements) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EA7E0)
[Address] EAT @explorer.exe (GdipSetMetafileDownLevelRasterizationLimit) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370A068)
[Address] EAT @explorer.exe (GdipSetPageScale) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3710B1C)
[Address] EAT @explorer.exe (GdipSetPageUnit) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C9E40)
[Address] EAT @explorer.exe (GdipSetPathFillMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BF4BC)
[Address] EAT @explorer.exe (GdipSetPathGradientBlend) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37178A8)
[Address] EAT @explorer.exe (GdipSetPathGradientCenterColor) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718444)
[Address] EAT @explorer.exe (GdipSetPathGradientCenterPoint) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717EDC)
[Address] EAT @explorer.exe (GdipSetPathGradientCenterPointI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717E68)
[Address] EAT @explorer.exe (GdipSetPathGradientFocusScales) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717104)
[Address] EAT @explorer.exe (GdipSetPathGradientGammaCorrection) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717BB0)
[Address] EAT @explorer.exe (GdipSetPathGradientLinearBlend) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718C10)
[Address] EAT @explorer.exe (GdipSetPathGradientPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37180E0)
[Address] EAT @explorer.exe (GdipSetPathGradientPresetBlend) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37175C4)
[Address] EAT @explorer.exe (GdipSetPathGradientSigmaBlend) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717504)
[Address] EAT @explorer.exe (GdipSetPathGradientSurroundColorsWithCount) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3718110)
[Address] EAT @explorer.exe (GdipSetPathGradientTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37189B4)
[Address] EAT @explorer.exe (GdipSetPathGradientWrapMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3717458)
[Address] EAT @explorer.exe (GdipSetPathMarker) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371F8E8)
[Address] EAT @explorer.exe (GdipSetPenBrushFill) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B7974)
[Address] EAT @explorer.exe (GdipSetPenColor) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36D08F8)
[Address] EAT @explorer.exe (GdipSetPenCompoundArray) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37157B0)
[Address] EAT @explorer.exe (GdipSetPenCustomEndCap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3716814)
[Address] EAT @explorer.exe (GdipSetPenCustomStartCap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37169C4)
[Address] EAT @explorer.exe (GdipSetPenDashArray) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37159D8)
[Address] EAT @explorer.exe (GdipSetPenDashCap197819) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3716D70)
[Address] EAT @explorer.exe (GdipSetPenDashOffset) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3715B44)
[Address] EAT @explorer.exe (GdipSetPenDashStyle) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36D0860)
[Address] EAT @explorer.exe (GdipSetPenEndCap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BABC0)
[Address] EAT @explorer.exe (GdipSetPenLineCap197819) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3716E18)
[Address] EAT @explorer.exe (GdipSetPenLineJoin) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BAC50)
[Address] EAT @explorer.exe (GdipSetPenMiterLimit) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37166A0)
[Address] EAT @explorer.exe (GdipSetPenMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3716548)
[Address] EAT @explorer.exe (GdipSetPenStartCap) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36BAB30)
[Address] EAT @explorer.exe (GdipSetPenTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3716368)
[Address] EAT @explorer.exe (GdipSetPenUnit) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3716F94)
[Address] EAT @explorer.exe (GdipSetPenWidth) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B6B50)
[Address] EAT @explorer.exe (GdipSetPixelOffsetMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36F346C)
[Address] EAT @explorer.exe (GdipSetPropertyItem) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C4558)
[Address] EAT @explorer.exe (GdipSetRenderingOrigin) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37116AC)
[Address] EAT @explorer.exe (GdipSetSmoothingMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B1DB8)
[Address] EAT @explorer.exe (GdipSetSolidFillColor) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36B6C1C)
[Address] EAT @explorer.exe (GdipSetStringFormatAlign) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708AC0)
[Address] EAT @explorer.exe (GdipSetStringFormatDigitSubstitution) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370843C)
[Address] EAT @explorer.exe (GdipSetStringFormatFlags) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708BE8)
[Address] EAT @explorer.exe (GdipSetStringFormatHotkeyPrefix) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708870)
[Address] EAT @explorer.exe (GdipSetStringFormatLineAlign) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708998)
[Address] EAT @explorer.exe (GdipSetStringFormatMeasurableCharacterRanges) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37084E8)
[Address] EAT @explorer.exe (GdipSetStringFormatTabStops) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708728)
[Address] EAT @explorer.exe (GdipSetStringFormatTrimming) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37082F8)
[Address] EAT @explorer.exe (GdipSetTextContrast) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3711264)
[Address] EAT @explorer.exe (GdipSetTextRenderingHint) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371130C)
[Address] EAT @explorer.exe (GdipSetTextureTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37189B4)
[Address] EAT @explorer.exe (GdipSetTextureWrapMode) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EDF10)
[Address] EAT @explorer.exe (GdipSetWorldTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36ED014)
[Address] EAT @explorer.exe (GdipShearMatrix) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371C19C)
[Address] EAT @explorer.exe (GdipStartPathFigure) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371FAC8)
[Address] EAT @explorer.exe (GdipStringFormatGetGenericDefault) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708DF8)
[Address] EAT @explorer.exe (GdipStringFormatGetGenericTypographic) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3708D90)
[Address] EAT @explorer.exe (GdipTestControl) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37081EC)
[Address] EAT @explorer.exe (GdipTransformMatrixPoints) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EC110)
[Address] EAT @explorer.exe (GdipTransformMatrixPointsI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EBFE4)
[Address] EAT @explorer.exe (GdipTransformPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371D804)
[Address] EAT @explorer.exe (GdipTransformPoints) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371098C)
[Address] EAT @explorer.exe (GdipTransformPointsI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37107AC)
[Address] EAT @explorer.exe (GdipTransformRegion) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371B374)
[Address] EAT @explorer.exe (GdipTranslateClip) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370BA4C)
[Address] EAT @explorer.exe (GdipTranslateClipI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC370B9EC)
[Address] EAT @explorer.exe (GdipTranslateLineTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371884C)
[Address] EAT @explorer.exe (GdipTranslateMatrix) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36EA68C)
[Address] EAT @explorer.exe (GdipTranslatePathGradientTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371884C)
[Address] EAT @explorer.exe (GdipTranslatePenTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3715FB8)
[Address] EAT @explorer.exe (GdipTranslateRegion) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371B4BC)
[Address] EAT @explorer.exe (GdipTranslateRegionI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371B45C)
[Address] EAT @explorer.exe (GdipTranslateTextureTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371884C)
[Address] EAT @explorer.exe (GdipTranslateWorldTransform) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36C7EEC)
[Address] EAT @explorer.exe (GdipVectorTransformMatrixPoints) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371C038)
[Address] EAT @explorer.exe (GdipVectorTransformMatrixPointsI) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371BE78)
[Address] EAT @explorer.exe (GdipWarpPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371D914)
[Address] EAT @explorer.exe (GdipWidenPath) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371DA68)
[Address] EAT @explorer.exe (GdipWindingModeOutline) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC371DBD0)
[Address] EAT @explorer.exe (GdiplusNotificationHook) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC3720510)
[Address] EAT @explorer.exe (GdiplusNotificationUnhook) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC37204AC)
[Address] EAT @explorer.exe (GdiplusShutdown) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36A88CC)
[Address] EAT @explorer.exe (GdiplusStartup) : WINMMBASE.dll -> HOOKED (C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.9200.16518_none_726fbfe0cc22f012\gdiplus.dll @ 0xC36A32B0)

¤¤¤ Externí včelstvo: ¤¤¤

¤¤¤ Nákaza : ¤¤¤

¤¤¤ Soubor HOSTS: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost
127.0.0.1 rad.msn.com
127.0.0.1 live.rads.msn.com
127.0.0.1 ads1.msn.com
127.0.0.1 static.2mdn.net
127.0.0.1 g.msn.com
127.0.0.1 a.ads2.msads.net
127.0.0.1 b.ads2.msads.net
127.0.0.1 ac3.msn.com
127.0.0.1 pagead.googlesyndication.com
127.0.0.1 pagead2.googlesyndication.com


¤¤¤ Kontrola MBR: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] af2d5d26254f379ef01a9d18b0ba1e96
[BSP] e5564d3a591cf8403f708aa9e7a52e9a : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 350 MB
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 718848 | Size: 150775 MB
2 - [XXXXXX] COMPAQ (0x12) [VISIBLE] Offset (sectors): 309506048 | Size: 1500 MB
3 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 312578048 | Size: 801242 MB
User = LL1 ... OK!
User = LL2 ... OK!

Dokončeno : << RKreport[0]_D_05102014_135133.txt >>
RKreport[0]_S_05102014_095206.txt;RKreport[0]_S_05102014_134543.txt
PHP, Nette, MySQL, C#, TypeScript, Python
IntelliJ Idea, Docker, Opera browser, Linux Mint
iPhone XS
Raspberry PI 3 (KODI, Raspbian)
XBox One S, PS 4, nVidia GeForce NOW

Uživatelský avatar
CZechBoY
Master Level 9.5
Master Level 9.5
Příspěvky: 8813
Registrován: srpen 08
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Nejdou zabíjet procesy

Příspěvekod CZechBoY » 10 kvě 2014 13:58

13:56:43.0806 2600 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
13:56:45.0809 2600 ============================================================
13:56:45.0809 2600 Current date / time: 2014/05/10 13:56:45.0809
13:56:45.0809 2600 SystemInfo:
13:56:45.0809 2600
13:56:45.0809 2600 OS Version: 6.2.9200 ServicePack: 0.0
13:56:45.0809 2600 Product type: Workstation
13:56:45.0809 2600 ComputerName: NTB
13:56:45.0809 2600 UserName: czech_000
13:56:45.0810 2600 Windows directory: C:\Windows
13:56:45.0810 2600 System windows directory: C:\Windows
13:56:45.0810 2600 Running under WOW64
13:56:45.0810 2600 Processor architecture: Intel x64
13:56:45.0810 2600 Number of processors: 4
13:56:45.0810 2600 Page size: 0x1000
13:56:45.0810 2600 Boot type: Normal boot
13:56:45.0810 2600 ============================================================
13:56:46.0148 2600 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:56:46.0151 2600 ============================================================
13:56:46.0151 2600 \Device\Harddisk0\DR0:
13:56:46.0151 2600 MBR partitions:
13:56:46.0151 2600 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xAF000
13:56:46.0151 2600 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xAF800, BlocksNum 0x1267B800
13:56:46.0151 2600 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x12A19000, BlocksNum 0x61CED000
13:56:46.0151 2600 ============================================================
13:56:46.0163 2600 C: <-> \Device\Harddisk0\DR0\Partition2
13:56:46.0208 2600 D: <-> \Device\Harddisk0\DR0\Partition3
13:56:46.0208 2600 ============================================================
13:56:46.0208 2600 Initialize success
13:56:46.0208 2600 ============================================================
13:56:47.0467 2192 ============================================================
13:56:47.0467 2192 Scan started
13:56:47.0467 2192 Mode: Manual;
13:56:47.0467 2192 ============================================================
13:56:47.0820 2192 ================ Scan system memory ========================
13:56:47.0820 2192 System memory - ok
13:56:47.0821 2192 ================ Scan services =============================
13:56:47.0990 2192 [ E890C46E4754F0DF51BAFCC8D2E07498 ] 1394ohci C:\Windows\System32\drivers\1394ohci.sys
13:56:47.0992 2192 1394ohci - ok
13:56:48.0016 2192 [ 4F18D4C7EA14F11A7211F60D553C03DB ] 3ware C:\Windows\system32\drivers\3ware.sys
13:56:48.0016 2192 3ware - ok
13:56:48.0049 2192 [ 975AABEB243B800C23626D6B652C5A9C ] ACPI C:\Windows\system32\drivers\ACPI.sys
13:56:48.0052 2192 ACPI - ok
13:56:48.0083 2192 [ DC968C37822117E576B933F34A2D130C ] acpiex C:\Windows\system32\Drivers\acpiex.sys
13:56:48.0084 2192 acpiex - ok
13:56:48.0102 2192 [ 0CA9F7C3A78227C21A0A7854E245CFB2 ] acpipagr C:\Windows\System32\drivers\acpipagr.sys
13:56:48.0102 2192 acpipagr - ok
13:56:48.0118 2192 [ 8EB8DA03B142D3DD1EB9ED8107A76C43 ] AcpiPmi C:\Windows\System32\drivers\acpipmi.sys
13:56:48.0118 2192 AcpiPmi - ok
13:56:48.0136 2192 [ CBCE725C5D86ABA7D2604E22951AA9B8 ] acpitime C:\Windows\System32\drivers\acpitime.sys
13:56:48.0136 2192 acpitime - ok
13:56:48.0191 2192 [ 3B42D95D20CD2AACDB0564471AE43ED7 ] ACPIVPC C:\Windows\System32\drivers\AcpiVpc.sys
13:56:48.0192 2192 ACPIVPC - ok
13:56:48.0311 2192 [ 00268E392FDAB9D494CA6D4B979E94BB ] AcuWVSSchedulerv8 D:\Program Files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe
13:56:48.0320 2192 AcuWVSSchedulerv8 - ok
13:56:48.0411 2192 [ 7C7E868E1D8096ED08D80FF7712BB9D8 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
13:56:48.0414 2192 AdobeFlashPlayerUpdateSvc - ok
13:56:48.0455 2192 [ 93C6388592B99925C1D1576E465BC80F ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
13:56:48.0458 2192 adp94xx - ok
13:56:48.0493 2192 [ D27763E0247292654E7F7D16444C7C72 ] adpahci C:\Windows\system32\drivers\adpahci.sys
13:56:48.0495 2192 adpahci - ok
13:56:48.0511 2192 [ 67B90070FF48F794AF19F9FCF0080D75 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
13:56:48.0513 2192 adpu320 - ok
13:56:48.0546 2192 [ 974AE60BF5B90E31412D93596C968E5B ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
13:56:48.0549 2192 AeLookupSvc - ok
13:56:48.0581 2192 [ 7C0E0EDF18D6CC565D7BFBB451709FA5 ] AFD C:\Windows\system32\drivers\afd.sys
13:56:48.0584 2192 AFD - ok
13:56:48.0607 2192 [ 01590377A5AB19E792528C628A2A68F9 ] agp440 C:\Windows\system32\drivers\agp440.sys
13:56:48.0608 2192 agp440 - ok
13:56:48.0636 2192 [ D1BE8E6E5B3AF23A4393AF1BF867977A ] ALG C:\Windows\System32\alg.exe
13:56:48.0637 2192 ALG - ok
13:56:48.0686 2192 [ 025E8C755BE293E50854D26D1BBE5133 ] AllUserInstallAgent C:\Windows\system32\AUInstallAgent.dll
13:56:48.0704 2192 AllUserInstallAgent - ok
13:56:48.0774 2192 [ 5A81054B824004B1ECC04F0034A1CDF9 ] AmdK8 C:\Windows\System32\drivers\amdk8.sys
13:56:48.0775 2192 AmdK8 - ok
13:56:48.0814 2192 [ B849D453E644FAB9BC8EF6DC8CA9C4C6 ] AmdPPM C:\Windows\System32\drivers\amdppm.sys
13:56:48.0815 2192 AmdPPM - ok
13:56:48.0827 2192 [ 35A0EB5AECB0FA3C41A2FB514A562304 ] amdsata C:\Windows\system32\drivers\amdsata.sys
13:56:48.0827 2192 amdsata - ok
13:56:48.0868 2192 [ 00452671904F5EE94B50BF0219C97164 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
13:56:48.0870 2192 amdsbs - ok
13:56:48.0891 2192 [ EA3FFE53E92E59C87E3ECA9BEB20D9B7 ] amdxata C:\Windows\system32\drivers\amdxata.sys
13:56:48.0892 2192 amdxata - ok
13:56:48.0938 2192 [ E71711D37C48AC40FD3E2866A5ABBA51 ] anvsnddrv C:\Windows\system32\drivers\anvsnddrv.sys
13:56:48.0939 2192 anvsnddrv - ok
13:56:48.0959 2192 [ 83B3682CE922FB0F415734B26D9D6233 ] AppID C:\Windows\system32\drivers\appid.sys
13:56:48.0960 2192 AppID - ok
13:56:48.0998 2192 [ CE2BEAD7F31816FF0AC490D048C969F9 ] AppIDSvc C:\Windows\System32\appidsvc.dll
13:56:48.0998 2192 AppIDSvc - ok
13:56:49.0035 2192 [ 4F750B7EFCB6520AE01E01D082D7D476 ] Appinfo C:\Windows\System32\appinfo.dll
13:56:49.0036 2192 Appinfo - ok
13:56:49.0131 2192 [ 221564CC7BE37611FE15EACF443E1BF6 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
13:56:49.0132 2192 Apple Mobile Device - ok
13:56:49.0158 2192 [ 2D14788C5D0836292BEB27BBE109BE56 ] AppMgmt C:\Windows\System32\appmgmts.dll
13:56:49.0160 2192 AppMgmt - ok
13:56:49.0180 2192 [ E933401B392387F4BE34DE8BAF1722A7 ] arc C:\Windows\system32\drivers\arc.sys
13:56:49.0181 2192 arc - ok
13:56:49.0215 2192 [ 07CA323EF2E8247A568AB0F3662AD644 ] arcsas C:\Windows\system32\drivers\arcsas.sys
13:56:49.0215 2192 arcsas - ok
13:56:49.0296 2192 [ 9A262EDD17F8473B91B333D6B031A901 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
13:56:49.0296 2192 aspnet_state - ok
13:56:49.0316 2192 [ 74DBAEC35366C4EE7670428808715A6A ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
13:56:49.0317 2192 AsyncMac - ok
13:56:49.0334 2192 [ A721FF570C2387E383BDDEA9632863C9 ] atapi C:\Windows\system32\drivers\atapi.sys
13:56:49.0334 2192 atapi - ok
13:56:49.0369 2192 [ BCD7A47EF587DC00DD61D12D9C2D1E44 ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
13:56:49.0372 2192 AudioEndpointBuilder - ok
13:56:49.0425 2192 [ 599B3F685A263A114FFAF3BE29C49C75 ] Audiosrv C:\Windows\System32\Audiosrv.dll
13:56:49.0433 2192 Audiosrv - ok
13:56:49.0467 2192 [ 89491EF71D5EA011127832C588002853 ] AxInstSV C:\Windows\System32\AxInstSV.dll
13:56:49.0469 2192 AxInstSV - ok
13:56:49.0504 2192 [ 87AB5BB072A3F128541D5B815F82FFDD ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
13:56:49.0507 2192 b06bdrv - ok
13:56:49.0546 2192 [ 81703BC5D68DEDBB086C2368FBE7B334 ] BasicDisplay C:\Windows\System32\drivers\BasicDisplay.sys
13:56:49.0547 2192 BasicDisplay - ok
13:56:49.0561 2192 [ 5EC68164E14D25675C98BBB5F09E8606 ] BasicRender C:\Windows\System32\drivers\BasicRender.sys
13:56:49.0561 2192 BasicRender - ok
13:56:49.0622 2192 [ 89143A7BA7850F5C7E61B43BB44B6418 ] BDESVC C:\Windows\System32\bdesvc.dll
13:56:49.0624 2192 BDESVC - ok
13:56:49.0654 2192 [ 9E7AEA59776D904607985AFFE7E5E183 ] Beep C:\Windows\system32\drivers\Beep.sys
13:56:49.0654 2192 Beep - ok
13:56:49.0697 2192 [ 53AA55632B94622F2DC3695E86EF9363 ] BFE C:\Windows\System32\bfe.dll
13:56:49.0705 2192 BFE - ok
13:56:49.0755 2192 [ D598C44A7072D3108D8D8102EC5E07F7 ] BITS C:\Windows\System32\qmgr.dll
13:56:49.0762 2192 BITS - ok
13:56:49.0858 2192 [ 4D87518BA68C308299441337C55F5427 ] Bluetooth Device Monitor C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
13:56:49.0867 2192 Bluetooth Device Monitor - ok
13:56:49.0912 2192 [ 19786E2114E2FCB4EAA30808E9D4FB9A ] Bluetooth OBEX Service C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
13:56:49.0919 2192 Bluetooth OBEX Service - ok
13:56:49.0967 2192 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service D:\Program Files\Bonjour\mDNSResponder.exe
13:56:49.0972 2192 Bonjour Service - ok
13:56:50.0027 2192 [ B17AC10B47C7FCB44D22A1F06415840E ] bowser C:\Windows\system32\DRIVERS\bowser.sys
13:56:50.0028 2192 bowser - ok
13:56:50.0070 2192 [ 038FA1B55531E7020DB705B42FCCE373 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
13:56:50.0073 2192 BrokerInfrastructure - ok
13:56:50.0112 2192 [ 310068BDA80B1D55C36580FD8A873FAF ] Browser C:\Windows\System32\browser.dll
13:56:50.0114 2192 Browser - ok
13:56:50.0149 2192 [ 6695200F455E251F0BCC9CE4D0978D59 ] BthAvrcpTg C:\Windows\System32\drivers\BthAvrcpTg.sys
13:56:50.0149 2192 BthAvrcpTg - ok
13:56:50.0181 2192 [ A8B20D852B07AE19A13B5D47EC4E4C3B ] BthEnum C:\Windows\System32\drivers\BthEnum.sys
13:56:50.0181 2192 BthEnum - ok
13:56:50.0200 2192 [ 616EB8748C988AEE98D93DA141C3D3B4 ] BthHFEnum C:\Windows\System32\drivers\bthhfenum.sys
13:56:50.0200 2192 BthHFEnum - ok
13:56:50.0238 2192 [ DCB4EBD928A6FB368BE6CAE522412DE1 ] bthhfhid C:\Windows\System32\drivers\BthHFHid.sys
13:56:50.0238 2192 bthhfhid - ok
13:56:50.0269 2192 [ 42201C346F0B8C458E1E9CDE04D68A2C ] BthLEEnum C:\Windows\system32\DRIVERS\BthLEEnum.sys
13:56:50.0270 2192 BthLEEnum - ok
13:56:50.0300 2192 [ 033916CE8784A848B9A3D686B7F66D97 ] BTHMODEM C:\Windows\System32\drivers\bthmodem.sys
13:56:50.0301 2192 BTHMODEM - ok
13:56:50.0338 2192 [ 091BB978E9504D0AD14586929431A957 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
13:56:50.0339 2192 BthPan - ok
13:56:50.0369 2192 [ 13795CAA34239D97A7211E7F9D96E012 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
13:56:50.0376 2192 BTHPORT - ok
13:56:50.0407 2192 [ A4387C3D271959313E2577DB7BE8BA7A ] bthserv C:\Windows\system32\bthserv.dll
13:56:50.0409 2192 bthserv - ok
13:56:50.0426 2192 [ 1F715957F5236D30B6020A19A4271F6A ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
13:56:50.0427 2192 BTHUSB - ok
13:56:50.0469 2192 [ 4428C299BE7B9841ECFA82044B69FA6A ] btmaux C:\Windows\system32\DRIVERS\btmaux.sys
13:56:50.0470 2192 btmaux - ok
13:56:50.0528 2192 [ 7B31A8A9DC95B3634D896FD0F2814F19 ] btmhsf C:\Windows\system32\DRIVERS\btmhsf.sys
13:56:50.0536 2192 btmhsf - ok
13:56:50.0540 2192 catchme - ok
13:56:50.0584 2192 [ 990B1BABE6E81FB18E65A87EBEFB1772 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
13:56:50.0585 2192 cdfs - ok
13:56:50.0607 2192 [ 339BFF85D788268752DA8C9644B188EE ] cdrom C:\Windows\System32\drivers\cdrom.sys
13:56:50.0608 2192 cdrom - ok
13:56:50.0645 2192 [ BAF8F0F55BC300E5F882E521F054E345 ] CertPropSvc C:\Windows\System32\certprop.dll
13:56:50.0647 2192 CertPropSvc - ok
13:56:50.0675 2192 [ F64B7D1A37CC1D5F421D5359EEC81E2E ] circlass C:\Windows\System32\drivers\circlass.sys
13:56:50.0676 2192 circlass - ok
13:56:50.0685 2192 [ 9905168708DB68849B879B5548F68AB3 ] CLFS C:\Windows\system32\drivers\CLFS.sys
13:56:50.0688 2192 CLFS - ok
13:56:50.0717 2192 [ 2DC8538A2260647484A6C921CA837313 ] CmBatt C:\Windows\System32\drivers\CmBatt.sys
13:56:50.0717 2192 CmBatt - ok
13:56:50.0755 2192 [ E708BFF0473EC6B271EA46B65B16CA56 ] CNG C:\Windows\system32\Drivers\cng.sys
13:56:50.0759 2192 CNG - ok
13:56:50.0775 2192 [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] CompositeBus C:\Windows\System32\drivers\CompositeBus.sys
13:56:50.0776 2192 CompositeBus - ok
13:56:50.0781 2192 COMSysApp - ok
13:56:50.0809 2192 [ D9CB0782AF819548072AA45B70F8B22D ] condrv C:\Windows\system32\drivers\condrv.sys
13:56:50.0809 2192 condrv - ok
13:56:50.0881 2192 [ 06B278D3D74D3AD7FA8E8D8D6300F574 ] cphs C:\Windows\SysWow64\IntelCpHeciSvc.exe
13:56:50.0884 2192 cphs - ok
13:56:50.0915 2192 cpuz136 - ok
13:56:50.0954 2192 [ 5CE2742F063731EC10C1B2EE386A2C08 ] CryptSvc C:\Windows\system32\cryptsvc.dll
13:56:50.0956 2192 CryptSvc - ok
13:56:50.0996 2192 [ F2C69C3D98249DE14D4B2832516D4FD5 ] CSC C:\Windows\system32\drivers\csc.sys
13:56:50.0999 2192 CSC - ok
13:56:51.0064 2192 [ 22CCB6AFF617AAC6121DF6CDA5ABF3F4 ] CscService C:\Windows\System32\cscsvc.dll
13:56:51.0072 2192 CscService - ok
13:56:51.0100 2192 [ FAEF4C245BE832DB41B15DAAC336AFB7 ] dam C:\Windows\system32\drivers\dam.sys
13:56:51.0101 2192 dam - ok
13:56:51.0172 2192 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] DcomLaunch C:\Windows\system32\rpcss.dll
13:56:51.0178 2192 DcomLaunch - ok
13:56:51.0215 2192 [ C8650D1F61149AA546BDBC99172EBBC1 ] defragsvc C:\Windows\System32\defragsvc.dll
13:56:51.0219 2192 defragsvc - ok
13:56:51.0246 2192 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] DeviceAssociationService C:\Windows\system32\das.dll
13:56:51.0250 2192 DeviceAssociationService - ok
13:56:51.0279 2192 [ 799BE46D45D486704CE0F37CA5385262 ] DeviceInstall C:\Windows\system32\umpnpmgr.dll
13:56:51.0282 2192 DeviceInstall - ok
13:56:51.0317 2192 [ 431141C6859990824D17F71C30A78728 ] Dfsc C:\Windows\system32\Drivers\dfsc.sys
13:56:51.0318 2192 Dfsc - ok
13:56:51.0356 2192 [ 9E0E72222264745ADEB0E5AC680B0ED6 ] Dhcp C:\Windows\system32\dhcpcore.dll
13:56:51.0361 2192 Dhcp - ok
13:56:51.0394 2192 [ 3C736FAE17BA6F91BA37594AAB139CD0 ] discache C:\Windows\system32\drivers\discache.sys
13:56:51.0394 2192 discache - ok
13:56:51.0437 2192 [ AE3786294CC246A5403783E1B86A0168 ] disk C:\Windows\system32\drivers\disk.sys
13:56:51.0438 2192 disk - ok
13:56:51.0469 2192 [ 82A7C72593793FE1EADA7A305BD1567A ] dmvsc C:\Windows\System32\drivers\dmvsc.sys
13:56:51.0469 2192 dmvsc - ok
13:56:51.0510 2192 [ 066B9710B36AB550E01EEFCA52155968 ] Dnscache C:\Windows\System32\dnsrslvr.dll
13:56:51.0512 2192 Dnscache - ok
13:56:51.0538 2192 [ 9949AD2ABA168A618D46C799D6CC898C ] dot3svc C:\Windows\System32\dot3svc.dll
13:56:51.0541 2192 dot3svc - ok
13:56:51.0581 2192 [ 109FC3F80BF4F4DC5A071058074F13C1 ] DPS C:\Windows\system32\dps.dll
13:56:51.0584 2192 DPS - ok
13:56:51.0619 2192 [ 9C7C183F937951AE17C5B8B3259CF3FF ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
13:56:51.0619 2192 drmkaud - ok
13:56:51.0664 2192 [ F87F4AAAF6664906248D11D5E579A53B ] DsmSvc C:\Windows\System32\DeviceSetupManager.dll
13:56:51.0667 2192 DsmSvc - ok
13:56:51.0734 2192 [ E6AF4DF1817953D73C519B17CF849756 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
13:56:51.0742 2192 DXGKrnl - ok
13:56:51.0763 2192 [ 58BA473DD88F5FC1932282BA683AA03E ] Eaphost C:\Windows\System32\eapsvc.dll
13:56:51.0765 2192 Eaphost - ok
13:56:51.0832 2192 [ 5AB97B3282D7D6114949D1EB5C8598E4 ] ebdrv C:\Windows\system32\drivers\evbda.sys
13:56:51.0850 2192 ebdrv - ok
13:56:51.0894 2192 [ F702AB6181513303AB0FC8D59E52708B ] EFS C:\Windows\System32\lsass.exe
13:56:51.0896 2192 EFS - ok
13:56:51.0940 2192 [ 66D60BD9A4C05616ABECA2A901475098 ] EhStorClass C:\Windows\system32\drivers\EhStorClass.sys
13:56:51.0941 2192 EhStorClass - ok
13:56:51.0963 2192 [ A61D0F543024E458C0FE32352E1978E2 ] EhStorTcgDrv C:\Windows\system32\drivers\EhStorTcgDrv.sys
13:56:51.0964 2192 EhStorTcgDrv - ok
13:56:51.0988 2192 [ D790D058D67582DB9C84C2D33695FE6B ] ErrDev C:\Windows\System32\drivers\errdev.sys
13:56:51.0989 2192 ErrDev - ok
13:56:52.0052 2192 [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] EventSystem C:\Windows\system32\es.dll
13:56:52.0056 2192 EventSystem - ok
13:56:52.0139 2192 [ 21FFB87A70019E9B39C5A8469695ACBA ] EvtEng D:\Program Files\Intel\WiFi\bin\EvtEng.exe
13:56:52.0143 2192 EvtEng - ok
13:56:52.0164 2192 [ 7A4D6FEB8C52B3FE855E4DCDF9107E03 ] exfat C:\Windows\system32\drivers\exfat.sys
13:56:52.0166 2192 exfat - ok
13:56:52.0199 2192 [ 60996602A7111FD2D086E803F33E4282 ] fastfat C:\Windows\system32\drivers\fastfat.sys
13:56:52.0200 2192 fastfat - ok
13:56:52.0249 2192 [ F0E7F8382ED5E138B0DFA4CB5058BCFE ] Fax C:\Windows\system32\fxssvc.exe
13:56:52.0257 2192 Fax - ok
13:56:52.0284 2192 [ 73B2D11DF0B6E03A0CB0323218ACB3E4 ] fdc C:\Windows\System32\drivers\fdc.sys
13:56:52.0285 2192 fdc - ok
13:56:52.0301 2192 [ 0828E3E7BD77C89149EAD3232BFD38DB ] fdPHost C:\Windows\system32\fdPHost.dll
13:56:52.0302 2192 fdPHost - ok
13:56:52.0318 2192 [ 872506AAB591E8908DF4461475AF92DF ] FDResPub C:\Windows\system32\fdrespub.dll
13:56:52.0320 2192 FDResPub - ok
13:56:52.0366 2192 [ 0588950D93A426F97C7AAADB1A9B0458 ] fhsvc C:\Windows\system32\fhsvc.dll
13:56:52.0368 2192 fhsvc - ok
13:56:52.0374 2192 [ 88A9EBACD1058ABB237A6B4E96E7F397 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
13:56:52.0375 2192 FileInfo - ok
13:56:52.0391 2192 [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
13:56:52.0391 2192 Filetrace - ok
13:56:52.0487 2192 [ A4297244D4F817278A6AE45B1899CA9C ] FLEXnet Licensing Service 64 C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
13:56:52.0501 2192 FLEXnet Licensing Service 64 - ok
13:56:52.0513 2192 [ B1D4C168FF7B8579E3745888658FFB1D ] flpydisk C:\Windows\System32\drivers\flpydisk.sys
13:56:52.0513 2192 flpydisk - ok
13:56:52.0545 2192 [ B33EC133AE4E6C1881D2302D93D2467D ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
13:56:52.0547 2192 FltMgr - ok
13:56:52.0575 2192 [ B8AFE7A30D34C0E9FDBA81632294547C ] fltsrv C:\Windows\system32\DRIVERS\fltsrv.sys
13:56:52.0576 2192 fltsrv - ok
13:56:52.0630 2192 [ 0BCDC0FF11B984162B0CF0FF6E9E0146 ] FontCache C:\Windows\system32\FntCache.dll
13:56:52.0643 2192 FontCache - ok
13:56:52.0737 2192 [ 0B56259F5611787222A04A8F254E51D4 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
13:56:52.0737 2192 FontCache3.0.0.0 - ok
13:56:52.0781 2192 [ A5F7873A39E4E9FAAAE59B7E9E36B705 ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
13:56:52.0782 2192 FsDepends - ok
13:56:52.0816 2192 [ A6DD7D491F587F4BC13FB972977DC8E8 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
13:56:52.0817 2192 Fs_Rec - ok
13:56:52.0850 2192 [ 340BA7CABB1F314E3650A7EF59F0A371 ] FTDIBUS C:\Windows\system32\drivers\ftdibus.sys
13:56:52.0851 2192 FTDIBUS - ok
13:56:52.0876 2192 [ A19D6F0356DBABB94293894B84C27D27 ] FTSER2K C:\Windows\system32\drivers\ftser2k.sys
13:56:52.0877 2192 FTSER2K - ok
13:56:52.0985 2192 [ 014195B03B378CFEAA029958CBC53695 ] fussvc C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe
13:56:52.0987 2192 fussvc - ok
13:56:53.0033 2192 [ B99C240DEA85007044E178C1C9C75659 ] Futuremark SystemInfo Service C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
13:56:53.0034 2192 Futuremark SystemInfo Service - ok
13:56:53.0069 2192 [ C1646A95EAC515F60CDB2A7A8A013C1E ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
13:56:53.0072 2192 fvevol - ok
13:56:53.0106 2192 [ A969D92973DFA895E7776B4BFE36DBB2 ] FxPPM C:\Windows\System32\drivers\fxppm.sys
13:56:53.0106 2192 FxPPM - ok
13:56:53.0125 2192 [ 52BC441E07A827EBAB70CDC7EAEDB28D ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
13:56:53.0125 2192 gagp30kx - ok
13:56:53.0152 2192 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
13:56:53.0153 2192 GEARAspiWDM - ok
13:56:53.0179 2192 [ 721F8EEF5E9747F32670DEFF7FB92541 ] gencounter C:\Windows\System32\drivers\vmgencounter.sys
13:56:53.0179 2192 gencounter - ok
13:56:53.0246 2192 GGSAFERDriver - ok
13:56:53.0276 2192 [ 77EBF3E9386DAA51551AF429052D88D0 ] giveio C:\Windows\giveio.sys
13:56:53.0277 2192 giveio - ok
13:56:53.0309 2192 [ FC2B8B06BDBD3B6457F5A3DA9AD2410E ] GPIOClx0101 C:\Windows\system32\Drivers\msgpioclx.sys
13:56:53.0310 2192 GPIOClx0101 - ok
13:56:53.0361 2192 [ 5358678C6370F2ADC5291849F6503262 ] gpsvc C:\Windows\System32\gpsvc.dll
13:56:53.0376 2192 gpsvc - ok
13:56:53.0406 2192 [ C41EB965A9DC4844F156E628F75AE876 ] Hamachi C:\Windows\system32\DRIVERS\Hamdrv.sys
13:56:53.0406 2192 Hamachi - ok
13:56:53.0507 2192 [ C57174C191F04B07A9F24320C57888E1 ] Hamachi2Svc D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
13:56:53.0528 2192 Hamachi2Svc - ok
13:56:53.0567 2192 [ 630555943E5A3FE21010CE91EC7FC84F ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:56:53.0569 2192 HdAudAddService - ok
13:56:53.0593 2192 [ 7D87B5B6C7188D553E11B59DC7F0B111 ] HDAudBus C:\Windows\System32\drivers\HDAudBus.sys
13:56:53.0594 2192 HDAudBus - ok
13:56:53.0616 2192 [ 3F76BBA53D65E85A7F53E7A71082082C ] HidBatt C:\Windows\System32\drivers\HidBatt.sys
13:56:53.0617 2192 HidBatt - ok
13:56:53.0652 2192 [ 085F150D002B7F0153D3C06DDF33A143 ] HidBth C:\Windows\System32\drivers\hidbth.sys
13:56:53.0653 2192 HidBth - ok
13:56:53.0664 2192 [ CC4A07E51D89575CAB6F4EB590D87CD4 ] hidi2c C:\Windows\System32\drivers\hidi2c.sys
13:56:53.0665 2192 hidi2c - ok
13:56:53.0674 2192 [ DC96F7DACB777CDEAEF9958A50BFDA06 ] HidIr C:\Windows\System32\drivers\hidir.sys
13:56:53.0675 2192 HidIr - ok
13:56:53.0713 2192 [ FAC37D7B3D6354A5A5E19A45B50B4008 ] hidserv C:\Windows\System32\hidserv.dll
13:56:53.0714 2192 hidserv - ok
13:56:53.0747 2192 [ 012C354B4AB48E9A7A657DF39E3A2073 ] HidUsb C:\Windows\System32\drivers\hidusb.sys
13:56:53.0747 2192 HidUsb - ok
13:56:53.0765 2192 [ 43F884B61A24377567CD0FEB35236334 ] hkmsvc C:\Windows\system32\kmsvc.dll
13:56:53.0767 2192 hkmsvc - ok
13:56:53.0794 2192 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF ] HomeGroupListener C:\Windows\system32\ListSvc.dll
13:56:53.0798 2192 HomeGroupListener - ok
13:56:53.0833 2192 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] HomeGroupProvider C:\Windows\system32\provsvc.dll
13:56:53.0838 2192 HomeGroupProvider - ok
13:56:53.0854 2192 [ 64DB7A8D97CA53DCCF93D0A1E08342CF ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
13:56:53.0855 2192 HpSAMD - ok
13:56:53.0889 2192 [ F4A91D985EB9D1D2717D538F3424603C ] HTTP C:\Windows\system32\drivers\HTTP.sys
13:56:53.0894 2192 HTTP - ok
13:56:53.0912 2192 [ 2A98301068801700906C06649860FE94 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
13:56:53.0913 2192 hwpolicy - ok
13:56:53.0934 2192 [ DC76901D82097C9E297F20C287CB9A27 ] hyperkbd C:\Windows\System32\drivers\hyperkbd.sys
13:56:53.0935 2192 hyperkbd - ok
13:56:53.0944 2192 [ 716413AB3CA12DE0A7222D28C1C9352C ] HyperVideo C:\Windows\system32\DRIVERS\HyperVideo.sys
13:56:53.0945 2192 HyperVideo - ok
13:56:53.0965 2192 [ C9E9CBF73AFFBFE3E801EFB516787BA3 ] i8042prt C:\Windows\System32\drivers\i8042prt.sys
13:56:53.0965 2192 i8042prt - ok
13:56:54.0008 2192 [ 0FE66A51D81A25AACEAAE4C26308121D ] iaStorA C:\Windows\system32\drivers\iaStorA.sys
13:56:54.0011 2192 iaStorA - ok
13:56:54.0053 2192 [ 584068E03829BC5C63F54B05E6244E97 ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
13:56:54.0054 2192 IAStorDataMgrSvc - ok
13:56:54.0093 2192 [ 5E394EBD26FD68AA9300332C46BEDD62 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
13:56:54.0095 2192 iaStorV - ok
13:56:54.0129 2192 [ 23E22B130EFE5A225E279467BE146317 ] ibtfltcoex C:\Windows\system32\DRIVERS\iBtFltCoex.sys
13:56:54.0129 2192 ibtfltcoex - ok
13:56:54.0158 2192 [ 83FF82FE209E7997067B375DAD6CF23D ] ICCS C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
13:56:54.0160 2192 ICCS - ok
13:56:54.0265 2192 [ 348214F96642FD4FEF630DE021BA3540 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
13:56:54.0294 2192 igfx - ok
13:56:54.0345 2192 [ 24847A06B84339FEEDE5CABF3D27D320 ] iirsp C:\Windows\system32\drivers\iirsp.sys
13:56:54.0346 2192 iirsp - ok
13:56:54.0393 2192 [ E455C83E029121270BED73CDAC381F37 ] IKEEXT C:\Windows\System32\ikeext.dll
13:56:54.0405 2192 IKEEXT - ok
13:56:54.0440 2192 [ F5495B38BFB9149925F54F65AB40EFBF ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
13:56:54.0443 2192 IntcDAud - ok
13:56:54.0531 2192 [ 441D5FAF24CC2EC115B654A55C52F0AF ] Intel(R) Wireless Bluetooth(R) 4.0 Radio Management C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
13:56:54.0532 2192 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management - ok
13:56:54.0571 2192 [ 4F37726CF764CA18A8A84F85EF3A7F24 ] intelide C:\Windows\system32\drivers\intelide.sys
13:56:54.0571 2192 intelide - ok
13:56:54.0648 2192 [ E15CDF68DD73423F15D4AC404793AF0D ] intelppm C:\Windows\System32\drivers\intelppm.sys
13:56:54.0650 2192 intelppm - ok
13:56:54.0675 2192 [ 8FCA66234A0933D796BB780B7953BAB9 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:56:54.0676 2192 IpFilterDriver - ok
13:56:54.0719 2192 [ C217B8D2E58C57A319B16125C3D4B69C ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
13:56:54.0732 2192 iphlpsvc - ok
13:56:54.0760 2192 [ 6E98A046A12AA113F8898AA5D612BD6E ] IPMIDRV C:\Windows\System32\drivers\IPMIDrv.sys
13:56:54.0761 2192 IPMIDRV - ok
13:56:54.0794 2192 [ 3969B9C218DD3FAA9F4ED2FFC3651C02 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
13:56:54.0795 2192 IPNAT - ok
13:56:54.0864 2192 [ 842D1EDD0F2A6E0E6631BB96BAAA01DE ] iPod Service D:\Program Files\iPod\bin\iPodService.exe
13:56:54.0871 2192 iPod Service - ok
13:56:54.0891 2192 [ 25CD7C4BB2863FFC2B0B311F0AEBF77C ] IRENUM C:\Windows\system32\drivers\irenum.sys
13:56:54.0891 2192 IRENUM - ok
13:56:54.0925 2192 [ D940C5BB9DC92E588533C19ABCC3D2C2 ] isapnp C:\Windows\system32\drivers\isapnp.sys
13:56:54.0926 2192 isapnp - ok
13:56:54.0967 2192 [ E6530FD4F61B40F338BF4355A21B9A09 ] iScsiPrt C:\Windows\System32\drivers\msiscsi.sys
13:56:54.0969 2192 iScsiPrt - ok
13:56:54.0983 2192 [ 8FBD94B69D6423E20ABCD59D86368B21 ] kbdclass C:\Windows\System32\drivers\kbdclass.sys
13:56:54.0984 2192 kbdclass - ok
13:56:55.0013 2192 [ E88C932ABDF8185A62C8F2FC7B051FB6 ] kbdhid C:\Windows\System32\drivers\kbdhid.sys
13:56:55.0013 2192 kbdhid - ok
13:56:55.0031 2192 [ FB6C185092E18011EF49989425C2AA87 ] kdnic C:\Windows\system32\DRIVERS\kdnic.sys
13:56:55.0031 2192 kdnic - ok
13:56:55.0056 2192 [ F702AB6181513303AB0FC8D59E52708B ] KeyIso C:\Windows\system32\lsass.exe
13:56:55.0058 2192 KeyIso - ok
13:56:55.0116 2192 [ DFA480F6DED551464F3A5B959F437800 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
13:56:55.0119 2192 KSecDD - ok
13:56:55.0311 2192 [ 127FB0AAD232BAAD2C9BBACD374F4FC5 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
13:56:55.0312 2192 KSecPkg - ok
13:56:55.0338 2192 [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
13:56:55.0339 2192 ksthunk - ok
13:56:55.0477 2192 [ 5825DBACEDC3812B5CF8D40B997BF210 ] KtmRm C:\Windows\system32\msdtckrm.dll
13:56:55.0492 2192 KtmRm - ok
13:56:55.0664 2192 [ 256EE31588257E8A555DBFAA13F1908E ] LanmanServer C:\Windows\System32\srvsvc.dll
13:56:55.0715 2192 LanmanServer - ok
13:56:55.0854 2192 [ 16650912BE5A94B40E0B3B4C39652B56 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:56:55.0863 2192 LanmanWorkstation - ok
13:56:55.0911 2192 [ BE166935083F9C38EDFDC21B9A7A679B ] LHDmgr C:\Windows\system32\DRIVERS\LhdX64.sys
13:56:55.0912 2192 LHDmgr - ok
13:56:55.0982 2192 [ CEEFD29FC551F289810B0B9381B321DC ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
13:56:55.0983 2192 lltdio - ok
13:56:56.0020 2192 [ BCF53485E0A94722CDE3C4A93CD8EB8C ] lltdsvc C:\Windows\System32\lltdsvc.dll
13:56:56.0024 2192 lltdsvc - ok
13:56:56.0043 2192 [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] lmhosts C:\Windows\System32\lmhsvc.dll
13:56:56.0045 2192 lmhosts - ok
13:56:56.0050 2192 lmimirr - ok
13:56:56.0084 2192 [ 022CDD12161B063D7852B1075BF3FFF2 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
13:56:56.0085 2192 LSI_SAS - ok
13:56:56.0101 2192 [ 07AD59D669B996F29F91817F0ECFA34F ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
13:56:56.0102 2192 LSI_SAS2 - ok
13:56:56.0183 2192 [ 216FB796AA4E252ACCE93B1BCB80B5EC ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
13:56:56.0184 2192 LSI_SCSI - ok
13:56:56.0211 2192 [ 5E80530AF37102488EE980B4A92AF99F ] LSI_SSS C:\Windows\system32\drivers\lsi_sss.sys
13:56:56.0212 2192 LSI_SSS - ok
13:56:56.0246 2192 [ A57BA284F5996FFD32DCDBC41A4657DB ] LSM C:\Windows\System32\lsm.dll
13:56:56.0251 2192 LSM - ok
13:56:56.0298 2192 [ 2BDC5D711FA61307CE6190D47C956368 ] luafv C:\Windows\system32\drivers\luafv.sys
13:56:56.0299 2192 luafv - ok
13:56:56.0339 2192 [ FD5465B876D55534117963FAAA4B9DFC ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
13:56:56.0339 2192 MBAMProtector - ok
13:56:56.0411 2192 [ 0E08BDD7326E657D59DB40BAD23D8169 ] MBAMScheduler D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
13:56:56.0421 2192 MBAMScheduler - ok
13:56:56.0442 2192 [ A8E7F3DB083EB0839DFC1C763CDD2594 ] MBAMService D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
13:56:56.0447 2192 MBAMService - ok
13:56:56.0503 2192 [ 3FFFB7F54CD7A792099C10402FCF8F56 ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys
13:56:56.0504 2192 MBAMWebAccessControl - ok
13:56:56.0543 2192 [ 9B0D829C3BE4E7472DB9DD2B79908E3C ] megasas C:\Windows\system32\drivers\megasas.sys
13:56:56.0544 2192 megasas - ok
13:56:56.0566 2192 [ ECC3F54C7AFC318271C4F0B4606D8DB0 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
13:56:56.0569 2192 MegaSR - ok
13:56:56.0610 2192 [ 2BB3EAE2EA641515D4B205CAB29E1624 ] MEIx64 C:\Windows\System32\drivers\HECIx64.sys
13:56:56.0611 2192 MEIx64 - ok
13:56:56.0658 2192 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] MMCSS C:\Windows\system32\mmcss.dll
13:56:56.0661 2192 MMCSS - ok
13:56:56.0693 2192 [ 780098AD5DA8A4822E2563984C85EF7B ] Modem C:\Windows\system32\drivers\modem.sys
13:56:56.0694 2192 Modem - ok
13:56:56.0731 2192 [ EA8EAD3F5B762F889CC7F3966625B48B ] monitor C:\Windows\System32\drivers\monitor.sys
13:56:56.0731 2192 monitor - ok
13:56:56.0748 2192 [ 618446B98C79776654340CE27C73485E ] mouclass C:\Windows\System32\drivers\mouclass.sys
13:56:56.0749 2192 mouclass - ok
13:56:56.0793 2192 [ C0ADEBED913295803B579ED288936CBB ] mouhid C:\Windows\System32\drivers\mouhid.sys
13:56:56.0793 2192 mouhid - ok
13:56:56.0819 2192 [ 89D263DBF08119CE16273991C120D6DD ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
13:56:56.0820 2192 mountmgr - ok
13:56:56.0849 2192 [ 528A5C2570F468155A1B3CF0A2FF5EBD ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
13:56:56.0850 2192 MozillaMaintenance - ok
13:56:56.0880 2192 [ 4CCBBD4944777CA100B9A6C2F149A46F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
13:56:56.0881 2192 mpsdrv - ok
13:56:56.0937 2192 [ 9DE3341BD4E14BC5FADFCAD3019F2D0D ] MpsSvc C:\Windows\system32\mpssvc.dll
13:56:56.0947 2192 MpsSvc - ok
13:56:56.0970 2192 [ 3D70147F55F1EC84EB9139ED7FFE48BC ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
13:56:56.0971 2192 MRxDAV - ok
13:56:57.0022 2192 [ 93179D48066918323628CB016D8C94DC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
13:56:57.0024 2192 mrxsmb - ok
13:56:57.0080 2192 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:56:57.0082 2192 mrxsmb10 - ok
13:56:57.0116 2192 [ 5C7DD2E5759FFCCD2C7341C1B90F2B26 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:56:57.0118 2192 mrxsmb20 - ok
13:56:57.0148 2192 [ 98487487D6B3797CA927E9D7B030AE13 ] MsBridge C:\Windows\system32\DRIVERS\bridge.sys
13:56:57.0149 2192 MsBridge - ok
13:56:57.0178 2192 [ 4A07458EB4F17573BD39F22029A991C1 ] MSDTC C:\Windows\System32\msdtc.exe
13:56:57.0181 2192 MSDTC - ok
13:56:57.0211 2192 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] Msfs C:\Windows\system32\drivers\Msfs.sys
13:56:57.0212 2192 Msfs - ok
13:56:57.0249 2192 [ C32A7A39B960A42BA9D4FBE47213CA03 ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys
13:56:57.0250 2192 msgpiowin32 - ok
13:56:57.0272 2192 [ D3857A767B91A061B408CCAB02DA4F40 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
13:56:57.0272 2192 mshidkmdf - ok
13:56:57.0284 2192 [ 839B48910FB1E887635C48F3EC11A05E ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys
13:56:57.0285 2192 mshidumdf - ok
13:56:57.0305 2192 [ 55C0DB741E3AB7463242B185B1C2997C ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
13:56:57.0305 2192 msisadrv - ok
13:56:57.0345 2192 [ 216C6B035A4BA5560E1255BD8E5BB89F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
13:56:57.0347 2192 MSiSCSI - ok
13:56:57.0351 2192 msiserver - ok
13:56:57.0363 2192 [ 509809566E49F4411055864EA8D437CD ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
13:56:57.0363 2192 MSKSSRV - ok
13:56:57.0437 2192 [ 63145201D6458E4958E572E7D6FC2604 ] MsLldp C:\Windows\system32\DRIVERS\mslldp.sys
13:56:57.0438 2192 MsLldp - ok
13:56:57.0460 2192 [ 99D526E803DB6D7FF290FD98B6204641 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
13:56:57.0461 2192 MSPCLOCK - ok
13:56:57.0472 2192 [ 06FA77C3E2A491ADCD704C5E73006269 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
13:56:57.0473 2192 MSPQM - ok
13:56:57.0501 2192 [ E134EC4DE11CF78CB01432D180710D84 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
13:56:57.0504 2192 MsRPC - ok
13:56:57.0552 2192 [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] mssmbios C:\Windows\System32\drivers\mssmbios.sys
13:56:57.0552 2192 mssmbios - ok
13:56:57.0579 2192 [ 72D66A05E0F99F2528F6C6204FD22AA1 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
13:56:57.0580 2192 MSTEE - ok
13:56:57.0591 2192 [ 8AAAE399FC255FA105D4158CBA289001 ] MTConfig C:\Windows\System32\drivers\MTConfig.sys
13:56:57.0592 2192 MTConfig - ok
13:56:57.0613 2192 [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A ] Mup C:\Windows\system32\Drivers\mup.sys
13:56:57.0614 2192 Mup - ok
13:56:57.0647 2192 [ 3A1E095277BBD406CEA8EA6B76950664 ] mvumis C:\Windows\system32\drivers\mvumis.sys
13:56:57.0648 2192 mvumis - ok
13:56:57.0696 2192 [ 53EE034F83E9A7A8E421572E385F67CD ] MyWiFiDHCPDNS D:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
13:56:57.0699 2192 MyWiFiDHCPDNS - ok
13:56:57.0736 2192 [ 4B18840511D720BA118D3017E8165875 ] napagent C:\Windows\system32\qagentRT.dll
13:56:57.0744 2192 napagent - ok
13:56:57.0778 2192 [ 43D7388A90A4C6EA346A4D6FF0377479 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
13:56:57.0781 2192 NativeWifiP - ok
13:56:57.0815 2192 [ 6A0C3996DA7DAE6D6939676D786EEEC4 ] NcaSvc C:\Windows\System32\ncasvc.dll
13:56:57.0818 2192 NcaSvc - ok
13:56:57.0838 2192 [ C982FE4CC91DECE2259F494FCEB4030F ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll
13:56:57.0841 2192 NcdAutoSetup - ok
13:56:57.0891 2192 [ A10E176F3B2BF83EDE7B5C4658C93B66 ] NDIS C:\Windows\system32\drivers\ndis.sys
13:56:57.0897 2192 NDIS - ok
13:56:57.0914 2192 [ 39C8A1D9D46F5E83A016BCAB72455284 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
13:56:57.0914 2192 NdisCap - ok
13:56:57.0950 2192 [ 762941932B7E4C588E48A577BA9D6440 ] NdisImPlatform C:\Windows\system32\DRIVERS\NdisImPlatform.sys
13:56:57.0951 2192 NdisImPlatform - ok
13:56:57.0982 2192 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
13:56:57.0982 2192 NdisTapi - ok
13:56:58.0007 2192 [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
13:56:58.0007 2192 Ndisuio - ok
13:56:58.0034 2192 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
13:56:58.0035 2192 NdisWan - ok
13:56:58.0041 2192 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NDISWANLEGACY C:\Windows\system32\DRIVERS\ndiswan.sys
13:56:58.0042 2192 NDISWANLEGACY - ok
13:56:58.0075 2192 [ 3730942D7DB2F8BB5F84542B7FF6F650 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
13:56:58.0076 2192 NDProxy - ok
13:56:58.0105 2192 [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] Ndu C:\Windows\system32\drivers\Ndu.sys
13:56:58.0105 2192 Ndu - ok
13:56:58.0125 2192 [ 7C203A76394F9AE68F69EEE5F9612C4A ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
13:56:58.0125 2192 NetBIOS - ok
13:56:58.0160 2192 [ 7CEC25C682D319D484630B3952C31A11 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
13:56:58.0162 2192 NetBT - ok
13:56:58.0196 2192 [ F702AB6181513303AB0FC8D59E52708B ] Netlogon C:\Windows\system32\lsass.exe
13:56:58.0197 2192 Netlogon - ok
13:56:58.0250 2192 [ 89519D29CBEC2121CA65CC29C4D345E0 ] Netman C:\Windows\System32\netman.dll
13:56:58.0254 2192 Netman - ok
13:56:58.0296 2192 [ 79FA9393C67EBBF92A56923592CF7A7C ] netprofm C:\Windows\System32\netprofmsvc.dll
13:56:58.0302 2192 netprofm - ok
13:56:58.0392 2192 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
13:56:58.0416 2192 NetTcpPortSharing - ok
13:56:58.0499 2192 [ 75B9B86878CC159FBC40C4F9202ADBE3 ] NETwNe64 C:\Windows\system32\DRIVERS\NETwew00.sys
13:56:58.0518 2192 NETwNe64 - ok
13:56:58.0546 2192 [ 12DD2800E4EEA37DC9AE256AD62423B4 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
13:56:58.0546 2192 nfrd960 - ok
13:56:58.0583 2192 [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] NlaSvc C:\Windows\System32\nlasvc.dll
13:56:58.0588 2192 NlaSvc - ok
13:56:58.0611 2192 [ DE7FCC77F4A503AF4CA6A47D49B3713D ] NPF C:\Windows\system32\drivers\NPF.sys
13:56:58.0612 2192 NPF - ok
13:56:58.0642 2192 [ 17E19A742FB30C002F8B43575451DBE1 ] Npfs C:\Windows\system32\drivers\Npfs.sys
13:56:58.0643 2192 Npfs - ok
13:56:58.0681 2192 [ 8ED299C30792544264E558BEA79F0947 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys
13:56:58.0681 2192 npsvctrig - ok
13:56:58.0718 2192 [ 832B5FDF0B5577713FD7F2465FCD0ACE ] nsi C:\Windows\system32\nsisvc.dll
13:56:58.0720 2192 nsi - ok
13:56:58.0744 2192 [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
13:56:58.0744 2192 nsiproxy - ok
13:56:58.0858 2192 [ 7BE3EDFFA3216F989A6BDCB14795DD08 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
13:56:58.0868 2192 Ntfs - ok
13:56:58.0889 2192 [ 4163ADE07DB51843AE31F65B94F5398D ] Null C:\Windows\system32\drivers\Null.sys
13:56:58.0890 2192 Null - ok
13:56:59.0150 2192 [ 52B33E12FF8C9E219CAEC1BB4A5F5E4C ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
13:56:59.0220 2192 nvlddmkm - ok
13:56:59.0319 2192 [ 6822CA012769844EB14FD6634F22C4F6 ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
13:56:59.0328 2192 NvNetworkService - ok
13:56:59.0357 2192 [ FACB0871B4480935F47234362F2FAE26 ] nvpciflt C:\Windows\system32\DRIVERS\nvpciflt.sys
13:56:59.0358 2192 nvpciflt - ok
13:56:59.0406 2192 [ D6D34118263412D3AAA8348A9572B7F2 ] nvraid C:\Windows\system32\drivers\nvraid.sys
13:56:59.0407 2192 nvraid - ok
13:56:59.0430 2192 [ 27AFC428D1D32ABD04A86763A4EDDEA9 ] nvstor C:\Windows\system32\drivers\nvstor.sys
13:56:59.0431 2192 nvstor - ok
13:56:59.0840 2192 [ E13F48379AF383046E55C0C87C11CF63 ] NvStreamSvc D:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
13:57:00.0181 2192 NvStreamSvc - ok
13:57:00.0230 2192 [ 2B47EDD27365F9F5D8E87648BECF52C4 ] nvsvc C:\Windows\system32\nvvsvc.exe
13:57:00.0242 2192 nvsvc - ok
13:57:00.0274 2192 [ 50A7C3FEA78D11B546EA9B0C25FBC6AB ] nvvad_WaveExtensible C:\Windows\system32\drivers\nvvad64v.sys
13:57:00.0275 2192 nvvad_WaveExtensible - ok
13:57:00.0307 2192 [ 051CFB5107BAAE510419BDC41F8C4036 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
13:57:00.0308 2192 nv_agp - ok
13:57:00.0378 2192 [ 51863FE4C259460128DD176739583D50 ] OpenVPNService D:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe
13:57:00.0379 2192 OpenVPNService - ok
13:57:00.0457 2192 [ 30B5F9FB0C35AE6B4A0851D24CE2EE8B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
13:57:00.0458 2192 ose - ok
13:57:00.0502 2192 [ AB76700D764A342D7475FB8F47CAB18C ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
13:57:00.0507 2192 p2pimsvc - ok
13:57:00.0543 2192 [ 4319FD931DCD796435ECB5DB4A04FBA5 ] p2psvc C:\Windows\system32\p2psvc.dll
13:57:00.0552 2192 p2psvc - ok
13:57:00.0577 2192 [ 4563DAF8C6A740AD7F501E219BD10766 ] Parport C:\Windows\System32\drivers\parport.sys
13:57:00.0578 2192 Parport - ok
13:57:00.0613 2192 [ D6ACCF9F2EEEEA711C14EFD976E573F3 ] partmgr C:\Windows\system32\drivers\partmgr.sys
13:57:00.0614 2192 partmgr - ok
13:57:00.0658 2192 [ 4811D9EC53649105A5A8BEA661B0F936 ] PcaSvc C:\Windows\System32\pcasvc.dll
13:57:00.0665 2192 PcaSvc - ok
13:57:00.0691 2192 [ 4A003E8F718C1E6A2050CA98CD53E3E2 ] pci C:\Windows\system32\drivers\pci.sys
13:57:00.0693 2192 pci - ok
13:57:00.0717 2192 [ F9908D274D458220F91E89B54D78D837 ] pciide C:\Windows\system32\drivers\pciide.sys
13:57:00.0717 2192 pciide - ok
13:57:00.0756 2192 [ 84D19CB6102627932DCB5DFDF89FE269 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
13:57:00.0758 2192 pcmcia - ok
13:57:00.0781 2192 [ CEBBAD5391C2644560C55628A40BFD27 ] pcw C:\Windows\system32\drivers\pcw.sys
13:57:00.0782 2192 pcw - ok
13:57:00.0820 2192 [ 0698DEDEAD6A00AD0D468C687D830FBF ] pdc C:\Windows\system32\drivers\pdc.sys
13:57:00.0821 2192 pdc - ok
13:57:00.0865 2192 [ 61FE70659CD43E07F94DA4DC31DEC493 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
13:57:00.0870 2192 PEAUTH - ok
13:57:00.0939 2192 [ DF0D9BDCB600913F40FF125BF8CE1979 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
13:57:00.0964 2192 PeerDistSvc - ok
13:57:01.0040 2192 [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A ] PerfHost C:\Windows\SysWow64\perfhost.exe
13:57:01.0042 2192 PerfHost - ok
13:57:01.0090 2192 [ 6E84BFF58F7643499277F29DFA2F8C8D ] pla C:\Windows\system32\pla.dll
13:57:01.0104 2192 pla - ok
13:57:01.0153 2192 [ 799BE46D45D486704CE0F37CA5385262 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
13:57:01.0156 2192 PlugPlay - ok
13:57:01.0199 2192 [ 8E2414E818C26C4A9C70CB2B8567F04F ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
13:57:01.0202 2192 PNRPAutoReg - ok
13:57:01.0234 2192 [ AB76700D764A342D7475FB8F47CAB18C ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
13:57:01.0237 2192 PNRPsvc - ok
13:57:01.0294 2192 [ 0108C8E5176D590F242701EF5A62CC26 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
13:57:01.0303 2192 PolicyAgent - ok
13:57:01.0336 2192 [ F1E067F56373F11EA4B785CAE823740A ] Power C:\Windows\system32\umpo.dll
13:57:01.0342 2192 Power - ok
13:57:01.0387 2192 [ 362D47E5B4D67270DE4B8606036F4ADD ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
13:57:01.0388 2192 PptpMiniport - ok
13:57:01.0705 2192 [ 9D59831262CAD44E709D695FC9D5E7AB ] PrintNotify C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
13:57:01.0731 2192 PrintNotify - ok
13:57:01.0765 2192 [ DD979EB6A7212F60E4AFBE96EDC7AE6D ] Processor C:\Windows\System32\drivers\processr.sys
13:57:01.0766 2192 Processor - ok
13:57:01.0810 2192 [ 429E8502AD2227CF88F8840FC5BD590D ] ProfSvc C:\Windows\system32\profsvc.dll
13:57:01.0814 2192 ProfSvc - ok
13:57:01.0854 2192 [ EB8034147D4820CD31BFCB11A2A652DF ] Psched C:\Windows\system32\DRIVERS\pacer.sys
13:57:01.0855 2192 Psched - ok
13:57:01.0899 2192 [ 0AFBF333B6F87A2F598EAB379AF100B8 ] QWAVE C:\Windows\system32\qwave.dll
13:57:01.0903 2192 QWAVE - ok
13:57:01.0919 2192 [ 13D47BB0CCA2FC51BD15F8E85C6A078E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
13:57:01.0920 2192 QWAVEdrv - ok
13:57:01.0946 2192 [ 873C60F8178100557740A832FCE10B5F ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
13:57:01.0946 2192 RasAcd - ok
13:57:01.0972 2192 [ 69B93F623B130976243ECA3D84CC99CA ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
13:57:01.0973 2192 RasAgileVpn - ok
13:57:02.0014 2192 [ 005F6E54C4A2DA4EBF68FB0392CE8BB0 ] RasAuto C:\Windows\System32\rasauto.dll
13:57:02.0017 2192 RasAuto - ok
13:57:02.0042 2192 [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
13:57:02.0043 2192 Rasl2tp - ok
13:57:02.0088 2192 [ C923C785A2DE0B396AD6D13ACAFF2DE9 ] RasMan C:\Windows\System32\rasmans.dll
13:57:02.0093 2192 RasMan - ok
13:57:02.0115 2192 [ 00695B9C2DB6111064499C529E90C042 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
13:57:02.0116 2192 RasPppoe - ok
13:57:02.0122 2192 [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
13:57:02.0122 2192 RasSstp - ok
13:57:02.0165 2192 [ CA03D642ACE58E1BA54E4B383F91CD69 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
13:57:02.0168 2192 rdbss - ok
13:57:02.0195 2192 [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] rdpbus C:\Windows\System32\drivers\rdpbus.sys
13:57:02.0195 2192 rdpbus - ok
13:57:02.0202 2192 [ B2A3AD74FF2E2FFA73AF2567108231B3 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
13:57:02.0203 2192 RDPDR - ok
13:57:02.0248 2192 [ 57F4787E4602A3FCA719C0A33137C6DA ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
13:57:02.0248 2192 RdpVideoMiniport - ok
13:57:02.0264 2192 [ B3CB0721E81E30419CE7D837EF4EA151 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
13:57:02.0265 2192 RDPWD - ok
13:57:02.0291 2192 [ 62C1F8A0685FE07E998AA296C4F697C4 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
13:57:02.0292 2192 rdyboost - ok
13:57:02.0386 2192 [ 1791B1C8C72E13D193ADE659E7DB87C1 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
13:57:02.0387 2192 RegSrvc - ok
13:57:02.0431 2192 [ 3663CCF243EE0C04E9F6F91ED1737273 ] RemoteAccess C:\Windows\System32\mprdim.dll
13:57:02.0434 2192 RemoteAccess - ok
13:57:02.0475 2192 [ E80DD61E52EDFFF9DA1ED7260A68855B ] RemoteRegistry C:\Windows\system32\regsvc.dll
13:57:02.0478 2192 RemoteRegistry - ok
13:57:02.0519 2192 [ CCBFCABDFE2BC22F0645CEAADDB36004 ] RFCOMM C:\Windows\System32\drivers\rfcomm.sys
13:57:02.0520 2192 RFCOMM - ok
13:57:02.0560 2192 [ 73F2E030B5C24E4E41401B5F0D59E6FD ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
13:57:02.0563 2192 RpcEptMapper - ok
13:57:02.0607 2192 [ 10B21284B3D964AB3DC45490E57D422E ] RpcLocator C:\Windows\system32\locator.exe
13:57:02.0608 2192 RpcLocator - ok
13:57:02.0655 2192 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] RpcSs C:\Windows\system32\rpcss.dll
13:57:02.0661 2192 RpcSs - ok
13:57:02.0688 2192 [ E04E770DD198B9399640717145E79EBF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
13:57:02.0689 2192 rspndr - ok
13:57:02.0734 2192 [ 55E66BAE5B30E09FDE217FBF0CDAA579 ] RSUSBVSTOR C:\Windows\System32\Drivers\RtsUVStor.sys
13:57:02.0736 2192 RSUSBVSTOR - ok
13:57:02.0766 2192 [ 15923AA360F7675D3D43C9669316A0BA ] RTL8168 C:\Windows\system32\DRIVERS\Rt630x64.sys
13:57:02.0770 2192 RTL8168 - ok
13:57:02.0938 2192 [ 02FE42ED9CBB4CBE806ED1E906D7AC8F ] rtsuvc C:\Windows\system32\DRIVERS\rtsuvc.sys
13:57:02.0983 2192 rtsuvc - ok
13:57:03.0034 2192 [ 752EC7DCD2F96871A3857EEE6AFE965A ] s3cap C:\Windows\System32\drivers\vms3cap.sys
13:57:03.0034 2192 s3cap - ok
13:57:03.0077 2192 [ F702AB6181513303AB0FC8D59E52708B ] SamSs C:\Windows\system32\lsass.exe
13:57:03.0078 2192 SamSs - ok
13:57:03.0091 2192 [ 9C7B28CE0D136DB226E24DB3BC817F92 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
13:57:03.0092 2192 sbp2port - ok
13:57:03.0125 2192 [ 14316954FCE79C9DE5A0AFF9D42C83AA ] SCardSvr C:\Windows\System32\SCardSvr.dll
13:57:03.0129 2192 SCardSvr - ok
13:57:03.0159 2192 [ 5D7733A12756B267FCA021672B26BC9E ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
13:57:03.0160 2192 scfilter - ok
13:57:03.0206 2192 [ ED40ED9A65F3E79A8C43DD50C5FDADBF ] Schedule C:\Windows\system32\schedsvc.dll
13:57:03.0219 2192 Schedule - ok
13:57:03.0259 2192 [ BAF8F0F55BC300E5F882E521F054E345 ] SCPolicySvc C:\Windows\System32\certprop.dll
13:57:03.0260 2192 SCPolicySvc - ok
13:57:03.0302 2192 [ F58B030A0664385C707B8C1C63682041 ] sdbus C:\Windows\System32\drivers\sdbus.sys
13:57:03.0303 2192 sdbus - ok
13:57:03.0328 2192 [ 92968277ED491E4B3DDA361E3952361E ] SDRSVC C:\Windows\System32\SDRSVC.dll
13:57:03.0332 2192 SDRSVC - ok
13:57:03.0371 2192 [ BB107AA9980B0DA4E19A3A90C3BD4460 ] sdstor C:\Windows\System32\drivers\sdstor.sys
13:57:03.0372 2192 sdstor - ok
13:57:03.0394 2192 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
13:57:03.0395 2192 secdrv - ok
13:57:03.0411 2192 [ CD282626738B6BC92B6E7CD0AAE95B63 ] seclogon C:\Windows\system32\seclogon.dll
13:57:03.0414 2192 seclogon - ok
13:57:03.0451 2192 [ 9C51620998F0763039DFA6BF68E475ED ] SENS C:\Windows\system32\sens.dll
13:57:03.0453 2192 SENS - ok
13:57:03.0500 2192 [ DDA4CAF29D8C0A297F886BFE561E6659 ] SensorsSimulatorDriver C:\Windows\system32\DRIVERS\WUDFRd.sys
13:57:03.0501 2192 SensorsSimulatorDriver - ok
13:57:03.0523 2192 [ 0D50B4B860DAB65241628D04CD33ACAE ] SensrSvc C:\Windows\system32\sensrsvc.dll
13:57:03.0526 2192 SensrSvc - ok
13:57:03.0545 2192 [ 87C46B239A7EEF30FDFDD5E9BD46130C ] SerCx C:\Windows\system32\drivers\SerCx.sys
13:57:03.0545 2192 SerCx - ok
13:57:03.0558 2192 [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] Serenum C:\Windows\System32\drivers\serenum.sys
13:57:03.0559 2192 Serenum - ok
13:57:03.0575 2192 [ F640A0A218BBF857F1D04A15D7D939F6 ] Serial C:\Windows\System32\drivers\serial.sys
13:57:03.0575 2192 Serial - ok
13:57:03.0594 2192 [ F1A5F56B2620B862CC28FF96A0A6DAAB ] sermouse C:\Windows\System32\drivers\sermouse.sys
13:57:03.0594 2192 sermouse - ok
13:57:03.0623 2192 [ CB60A60340788C8D6DE2A269D28086AB ] SessionEnv C:\Windows\system32\sessenv.dll
13:57:03.0628 2192 SessionEnv - ok
13:57:03.0656 2192 [ DDA1B38A59DE5096E2619D4CFDE01F4A ] sfdrv01a C:\Windows\system32\drivers\sfdrv01a.sys
13:57:03.0656 2192 sfdrv01a - ok
13:57:03.0676 2192 [ 17F6BD95BF04B924F4C05CE78BEF8AE6 ] sfhlp02 C:\Windows\system32\drivers\sfhlp02.sys
13:57:03.0676 2192 sfhlp02 - ok
13:57:03.0688 2192 [ 7EE65419B29302C795714FF8073969A1 ] sfloppy C:\Windows\System32\drivers\sfloppy.sys
13:57:03.0689 2192 sfloppy - ok
13:57:03.0693 2192 sfrem01 - ok
13:57:03.0712 2192 [ C2FC1E7B64D844251A1AF6BCADFE4C14 ] sfsync04 C:\Windows\system32\drivers\sfsync04.sys
13:57:03.0713 2192 sfsync04 - ok
13:57:03.0772 2192 [ 090AE16F79C8EAD04E6031F863DA85F3 ] SharedAccess C:\Windows\System32\ipnathlp.dll
13:57:03.0777 2192 SharedAccess - ok
13:57:03.0824 2192 [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:57:03.0831 2192 ShellHWDetection - ok
13:57:03.0849 2192 [ 2560721D6F16D5B611C36A3A9D28C1B2 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
13:57:03.0849 2192 SiSRaid2 - ok
13:57:03.0865 2192 [ 3AA8FDE1DBF65BB8B88B053529554A0D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
13:57:03.0866 2192 SiSRaid4 - ok
13:57:03.0896 2192 [ 165AB7677D53868AA61FB26B739C66DB ] SmbDrvI C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys
13:57:03.0897 2192 SmbDrvI - ok
13:57:03.0937 2192 [ BBFB94699C8C265A6AF5FD51BDE26DFC ] snapman C:\Windows\system32\DRIVERS\snapman.sys
13:57:03.0939 2192 snapman - ok
13:57:03.0955 2192 [ E660156A4588A84305CB772FD2C0DB21 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
13:57:03.0956 2192 SNMPTRAP - ok
13:57:03.0995 2192 [ F9369327409492097B0BB7CE86BD29DE ] Soluto C:\Windows\system32\DRIVERS\Soluto.sys
13:57:03.0995 2192 Soluto - ok
13:57:04.0060 2192 [ A58E8599AA15628CCCD991BFB0AC0EBC ] SolutoLauncherService D:\Program Files\Soluto\SolutoLauncherService.exe
13:57:04.0062 2192 SolutoLauncherService - ok
13:57:04.0104 2192 [ 0FA2D9E29AE6D321EC68DD8F1B9E1181 ] SolutoRemoteService D:\Program Files\Soluto\SolutoRemoteService.exe
13:57:04.0123 2192 SolutoRemoteService - ok
13:57:04.0141 2192 [ 151DBFF45C9190D3C85E3BD38423BA72 ] SolutoService D:\Program Files\Soluto\SolutoService.exe
13:57:04.0144 2192 SolutoService - ok
13:57:04.0179 2192 [ 9110193D93960E38B8692E4519C75D72 ] spaceport C:\Windows\system32\drivers\spaceport.sys
13:57:04.0181 2192 spaceport - ok
13:57:04.0206 2192 [ 3D8679C8DF52EB26EB7583A4E0A29202 ] SpbCx C:\Windows\system32\drivers\SpbCx.sys
13:57:04.0207 2192 SpbCx - ok
13:57:04.0247 2192 [ 52B9158CBF1E0B627634EF50B27FF14B ] Speechsrv D:\Program Files (x86)\LAN Voice Chat\Speechs.exe
13:57:04.0252 2192 Speechsrv - ok
13:57:04.0297 2192 [ 3F215BF2D4D8D6756298B25B579772C2 ] Spooler C:\Windows\System32\spoolsv.exe
13:57:04.0303 2192 Spooler - ok
13:57:04.0438 2192 [ 061A977C920FBE4BF71FF47C966DDDCA ] sppsvc C:\Windows\system32\sppsvc.exe
13:57:04.0467 2192 sppsvc - ok
13:57:04.0469 2192 ================ Scan global ===============================
13:57:04.0518 2192 [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\Windows\system32\basesrv.dll
13:57:04.0579 2192 [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\Windows\system32\winsrv.dll
13:57:04.0644 2192 [ BD7C6949984D19AAA609896B675E7357 ] C:\Windows\system32\sxssrv.dll
13:57:04.0763 2192 [ 8F226143046435C75C033B0C52E90FFE ] C:\Windows\system32\services.exe
13:57:04.0766 2192 [Global] - ok
13:57:04.0767 2192 ================ Scan MBR ==================================
13:57:04.0786 2192 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
13:57:05.0002 2192 \Device\Harddisk0\DR0 - ok
13:57:05.0002 2192 ================ Scan VBR ==================================
13:57:05.0005 2192 [ B00CB9DAC7D51A91064A82A5EFAD1DCF ] \Device\Harddisk0\DR0\Partition1
13:57:05.0006 2192 \Device\Harddisk0\DR0\Partition1 - ok
13:57:05.0015 2192 [ EC6C97A09A297816EDA0298FB02B8054 ] \Device\Harddisk0\DR0\Partition2
13:57:05.0017 2192 \Device\Harddisk0\DR0\Partition2 - ok
13:57:05.0037 2192 [ 70B59553A40A55F060B358862E35CB09 ] \Device\Harddisk0\DR0\Partition3
13:57:05.0038 2192 \Device\Harddisk0\DR0\Partition3 - ok
13:57:05.0039 2192 ============================================================
13:57:05.0039 2192 Scan finished
13:57:05.0039 2192 ============================================================
13:57:05.0051 5608 Detected object count: 0
13:57:05.0051 5608 Actual detected object count: 0
13:57:48.0121 4444 Deinitialize success
PHP, Nette, MySQL, C#, TypeScript, Python
IntelliJ Idea, Docker, Opera browser, Linux Mint
iPhone XS
Raspberry PI 3 (KODI, Raspbian)
XBox One S, PS 4, nVidia GeForce NOW

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Nejdou zabíjet procesy

Příspěvekod jaro3 » 10 kvě 2014 18:45

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "
- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud budou problémy , spusť ho v nouz. režimu.

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
CZechBoY
Master Level 9.5
Master Level 9.5
Příspěvky: 8813
Registrován: srpen 08
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Nejdou zabíjet procesy

Příspěvekod CZechBoY » 10 kvě 2014 19:19

Však ten roguekiller jsem mazal teď.. to mám mazat znova?
PHP, Nette, MySQL, C#, TypeScript, Python
IntelliJ Idea, Docker, Opera browser, Linux Mint
iPhone XS
Raspberry PI 3 (KODI, Raspbian)
XBox One S, PS 4, nVidia GeForce NOW

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Nejdou zabíjet procesy

Příspěvekod Orcus » 10 kvě 2014 20:21

Ne, nemaž.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

Uživatelský avatar
CZechBoY
Master Level 9.5
Master Level 9.5
Příspěvky: 8813
Registrován: srpen 08
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Nejdou zabíjet procesy

Příspěvekod CZechBoY » 26 čer 2014 12:29

ComboFix 14-06-24.01 - czech_000 . 06. 2014 12:02:40.1.4 - x64
Microsoft Windows 8 Pro 6.2.9200.0.1250.420.1029.18.3956.2262 [GMT 2:00]
Spuštěný z: c:\users\czech_000\Desktop\ComboFix.exe
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\czech_000\AppData\Local\assembly\tmp
c:\windows\SysWow64\SET756C.tmp
c:\windows\SysWow64\SETA06B.tmp
c:\windows\SysWow64\SETB1F4.tmp
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_NPF
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-05-26 do 2014-06-26 )))))))))))))))))))))))))))))))
.
.
2014-06-26 10:13 . 2014-06-26 10:13 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-06-26 10:13 . 2014-06-26 10:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-21 12:41 . 2014-06-21 13:10 -------- d-----w- c:\users\czech_000\AppData\Roaming\Audacity
2014-06-21 11:22 . 2014-06-21 11:22 -------- d-----w- c:\windows\SysWow64\NV
2014-06-21 11:22 . 2014-06-21 11:22 -------- d-----w- c:\windows\system32\NV
2014-06-21 11:03 . 2014-05-29 23:07 1291232 ----a-w- c:\windows\SysWow64\nvspbridge.dll
2014-06-21 11:03 . 2014-05-29 23:07 1715176 ----a-w- c:\windows\system32\nvspbridge64.dll
2014-06-21 11:02 . 2014-06-21 11:19 -------- d-----w- c:\windows\LastGood.Tmp
2014-06-21 11:02 . 2014-03-31 16:42 40392 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2014-06-21 11:02 . 2014-03-31 16:42 37320 ----a-w- c:\windows\system32\nvaudcap64v.dll
2014-06-21 11:02 . 2014-03-31 16:42 34760 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2014-06-18 08:50 . 2014-06-25 21:59 -------- d-----w- c:\users\czech_000\AppData\Local\Adobe
2014-06-16 18:54 . 2014-06-16 22:21 -------- d-----w- c:\users\czech_000\AppData\Roaming\TS3Client
2014-06-14 10:37 . 2014-05-24 02:46 3958784 ----a-w- c:\windows\system32\jscript9.dll
2014-06-14 10:37 . 2014-05-24 02:46 2650112 ----a-w- c:\windows\system32\iertutil.dll
2014-06-14 10:37 . 2014-05-24 01:25 2862080 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-06-14 10:36 . 2014-03-07 00:47 1419264 ----a-w- c:\windows\SysWow64\msxml3.dll
2014-06-14 10:36 . 2014-03-07 00:08 1845760 ----a-w- c:\windows\system32\msxml3.dll
2014-06-14 10:36 . 2014-04-03 11:22 2233176 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-06-13 22:56 . 2014-06-16 12:45 -------- d-----w- d:\program files (x86)\rFactor
2014-06-09 21:00 . 2014-06-09 21:00 -------- d-----w- d:\program files (x86)\Anki
2014-06-04 08:17 . 2014-06-04 08:17 -------- d-----w- d:\program files (x86)\iTunes
2014-06-04 08:17 . 2014-06-04 08:17 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-25 20:28 . 2014-04-21 15:27 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-06-14 13:29 . 2013-07-14 23:28 95414520 ----a-w- c:\windows\system32\MRT.exe
2014-05-31 05:16 . 2012-07-26 08:14 703992 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-31 05:16 . 2012-07-26 08:14 105464 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-29 23:07 . 2013-10-30 09:27 1122312 ----a-w- c:\windows\SysWow64\nvspcap.dll
2014-05-29 23:07 . 2013-10-30 09:27 1279480 ----a-w- c:\windows\system32\nvspcap64.dll
2014-05-20 02:44 . 2013-07-14 22:41 952952 ----a-w- c:\windows\system32\nvumdshimx.dll
2014-05-20 02:44 . 2013-07-14 22:41 837056 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2014-05-20 02:44 . 2013-07-14 22:41 3109248 ----a-w- c:\windows\system32\nvapi64.dll
2014-05-20 02:44 . 2013-07-14 22:41 2730208 ----a-w- c:\windows\SysWow64\nvapi.dll
2014-05-20 02:44 . 2013-07-14 22:41 166568 ----a-w- c:\windows\system32\nvinitx.dll
2014-05-20 02:44 . 2013-07-14 22:41 146480 ----a-w- c:\windows\SysWow64\nvinit.dll
2014-05-20 01:25 . 2013-07-14 22:43 6769096 ----a-w- c:\windows\system32\nvcpl.dll
2014-05-20 01:25 . 2013-07-14 22:43 3514144 ----a-w- c:\windows\system32\nvsvc64.dll
2014-05-20 01:25 . 2013-07-14 22:43 927520 ----a-w- c:\windows\system32\nvvsvc.exe
2014-05-20 01:25 . 2013-07-14 22:43 76064 ----a-w- c:\windows\system32\nv3dappshextr.dll
2014-05-20 01:25 . 2013-07-14 22:43 62808 ----a-w- c:\windows\system32\nvshext.dll
2014-05-20 01:25 . 2013-07-14 22:43 387528 ----a-w- c:\windows\system32\nvmctray.dll
2014-05-20 01:25 . 2013-07-14 22:43 2560968 ----a-w- c:\windows\system32\nvsvcr.dll
2014-05-20 01:25 . 2013-07-14 22:43 1078616 ----a-w- c:\windows\system32\nv3dappshext.dll
2014-05-20 01:25 . 2013-07-14 22:42 610592 ----a-w- c:\windows\SysWow64\oemdspif.dll
2014-05-14 23:49 . 2013-07-14 22:43 3774821 ----a-w- c:\windows\system32\nvcoproc.bin
2014-05-13 17:56 . 2014-04-28 16:56 17938608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2014-05-12 05:26 . 2014-04-21 15:27 64216 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-05-12 05:26 . 2014-01-28 20:03 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-05-12 05:25 . 2013-07-28 10:13 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-04-25 00:16 . 2014-04-25 00:16 1070232 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2014-04-19 09:39 . 2014-05-06 09:16 628024 ----a-w- c:\windows\system32\NotificationUI.exe
2014-04-19 08:45 . 2014-05-06 09:16 693760 ----a-w- c:\windows\system32\WSShared.dll
2014-04-19 08:45 . 2014-05-06 09:16 163840 ----a-w- c:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-19 06:57 . 2014-05-06 09:16 566784 ----a-w- c:\windows\SysWow64\WSShared.dll
2014-04-19 06:57 . 2014-05-06 09:16 124928 ----a-w- c:\windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-15 08:46 . 2014-04-15 08:46 46136 ---ha-w- c:\windows\system32\drivers\Hamdrv.sys
2014-04-14 18:13 . 2014-05-19 20:20 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-04-12 09:27 . 2014-05-23 08:18 172888 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-04-12 09:10 . 2014-05-23 08:18 578048 ----a-w- c:\windows\system32\winlogon.exe
2014-04-12 09:09 . 2014-05-23 08:18 208896 ----a-w- c:\windows\system32\wdigest.dll
2014-04-12 09:09 . 2014-05-23 08:18 1043968 ----a-w- c:\windows\system32\usercpl.dll
2014-04-12 09:09 . 2014-05-23 08:18 94720 ----a-w- c:\windows\system32\TSpkg.dll
2014-04-12 09:09 . 2014-05-23 08:18 588288 ----a-w- c:\windows\system32\SHCore.dll
2014-04-12 09:08 . 2014-05-23 08:18 318464 ----a-w- c:\windows\system32\msv1_0.dll
2014-04-12 09:08 . 2014-05-23 08:18 1281536 ----a-w- c:\windows\system32\lsasrv.dll
2014-04-12 09:08 . 2014-05-23 08:18 439808 ----a-w- c:\windows\system32\lsm.dll
2014-04-12 09:08 . 2014-05-23 08:18 827904 ----a-w- c:\windows\system32\kerberos.dll
2014-04-12 09:07 . 2014-05-23 08:18 20480 ----a-w- c:\windows\system32\credssp.dll
2014-04-12 07:23 . 2014-05-23 08:18 178688 ----a-w- c:\windows\SysWow64\wdigest.dll
2014-04-12 07:23 . 2014-05-23 08:18 961536 ----a-w- c:\windows\SysWow64\usercpl.dll
2014-04-12 07:23 . 2014-05-23 08:18 76800 ----a-w- c:\windows\SysWow64\TSpkg.dll
2014-04-12 07:23 . 2014-05-23 08:18 452608 ----a-w- c:\windows\SysWow64\SHCore.dll
2014-04-12 07:23 . 2014-05-23 08:18 273920 ----a-w- c:\windows\SysWow64\msv1_0.dll
2014-04-12 07:22 . 2014-05-23 08:18 666624 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-04-12 07:22 . 2014-05-23 08:18 17408 ----a-w- c:\windows\SysWow64\credssp.dll
2014-04-12 06:58 . 2014-05-23 08:18 14848 ----a-w- c:\windows\system32\workerdd.dll
2014-03-29 19:39 . 2013-08-31 23:07 1488160 ----a-w- c:\programdata\Microsoft\VisualStudio\11.0\1033\ResourceCache.dll
2014-03-29 19:39 . 2013-08-31 23:27 1496704 ----a-w- c:\programdata\Microsoft\VisualStudio\11.0\1029\ResourceCache.dll
2014-03-28 19:19 . 2014-05-23 08:18 35856 ----a-w- c:\windows\system32\drivers\WdBoot.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-18 08:20 222832 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-18 08:20 222832 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-18 08:20 222832 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2014-05-14 06:15 1730264 ----a-w- d:\program files (x86)\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2014-05-14 06:15 1730264 ----a-w- d:\program files (x86)\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2014-05-14 06:15 1730264 ----a-w- d:\program files (x86)\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-05-08 21444224]
"GarenaPlus"="d:\program files (x86)\Garena Plus\GarenaMessenger.exe" [2014-04-29 9936176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-07-16 56128]
"LogMeIn Hamachi Ui"="d:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2014-04-15 3814736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\
RescueTime.lnk - d:\program files (x86)\RescueTime\RescueTime.exe [2014-4-2 3343360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys;c:\windows\SYSNATIVE\drivers\sfdrv01a.sys [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AcuWVSSchedulerv8;Acunetix WVS Scheduler v8;d:\program files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe;d:\program files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe [x]
R3 anvsnddrv;AnvSoft Virtual Sound Device;c:\windows\system32\drivers\anvsnddrv.sys;c:\windows\SYSNATIVE\drivers\anvsnddrv.sys [x]
R3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [x]
R3 GGSAFERDriver;GGSAFER Driver;d:\program files (x86)\Garena Plus\Room\safedrv.sys;d:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;d:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;d:\program files\Intel\WiFi\bin\PanDhcpDns.exe;d:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 NETwNe64;Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 8 64 Bit;c:\windows\system32\DRIVERS\NETwew00.sys;c:\windows\SYSNATIVE\DRIVERS\NETwew00.sys [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
R3 SolutoRemoteService;Soluto Remote Service;d:\program files\Soluto\SolutoRemoteService.exe;d:\program files\Soluto\SolutoRemoteService.exe [x]
R3 Speechsrv;Glasovne poruke;d:\program files (x86)\LAN Voice Chat\Speechs.exe;d:\program files (x86)\LAN Voice Chat\Speechs.exe [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 SuperIO;Lenovo ASD HWM Driver;c:\windows\System32\drivers\spio.sys;c:\windows\SYSNATIVE\drivers\spio.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [x]
R3 TunngleService;TunngleService;d:\program files (x86)\Tunngle\TnglCtrl.exe;d:\program files (x86)\Tunngle\TnglCtrl.exe [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
R3 VBoxUSB;VirtualBox USB;c:\windows\System32\Drivers\VBoxUSB.sys;c:\windows\SYSNATIVE\Drivers\VBoxUSB.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 VsEtwService120;Visual Studio ETW Event Collection Service;d:\program files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe;d:\program files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [x]
S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys;c:\windows\SYSNATIVE\DRIVERS\fltsrv.sys [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys;c:\windows\SYSNATIVE\DRIVERS\LhdX64.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S0 Soluto;Soluto;c:\windows\system32\DRIVERS\Soluto.sys;c:\windows\SYSNATIVE\DRIVERS\Soluto.sys [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
S2 IAStorDataMgrSvc;Úložná technologie Intel® Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;c:\program files (x86)\Intel\Bluetooth\ibtrksrv.exe;c:\program files (x86)\Intel\Bluetooth\ibtrksrv.exe [x]
S2 MBAMService;MBAMService;d:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;d:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;d:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;d:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 SolutoLauncherService;Soluto Launcher Service;d:\program files\Soluto\SolutoLauncherService.exe;d:\program files\Soluto\SolutoLauncherService.exe [x]
S2 SolutoService;Soluto PCGenome Core Service;d:\program files\Soluto\SolutoService.exe;d:\program files\Soluto\SolutoService.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;d:\program files\Intel\WiFi\bin\ZeroConfigService.exe;d:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\System32\drivers\AcpiVpc.sys;c:\windows\SYSNATIVE\drivers\AcpiVpc.sys [x]
S3 BthLEEnum;Ovladač úspory energie technologie Bluetooth;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
S3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 NvStreamKms;NvStreamKms;d:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;d:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
S3 rtsuvc;Lenovo EasyCamera;c:\windows\system32\DRIVERS\rtsuvc.sys;c:\windows\SYSNATIVE\DRIVERS\rtsuvc.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-04-25 08:44 1078088 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.131\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-06-26 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-15 10:45]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-18 08:20 261744 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-18 08:20 261744 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-18 08:20 261744 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2014-05-14 06:18 2335960 ----a-w- d:\program files\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2014-05-14 06:18 2335960 ----a-w- d:\program files\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2014-05-14 06:18 2335960 ----a-w- d:\program files\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-19 172168]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-19 441992]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-05-29 2352072]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2013-07-14 17080376]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2013-07-14 191544]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-05-29 1279480]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshellex.dll" [2013-09-19 7818040]
"Soluto"="d:\program files\soluto\soluto.exe" [2013-08-17 1252896]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uLocal Page = %SystemRoot%\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SYSTEM32\blank.htm
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - d:\program files (x86)\MICROS~1\Office15\EXCEL.EXE/3000
IE: Inspect Element with DebugBar - d:\program files (x86)\Core Services\DebugBar\DebugInfoBar.dll/247
IE: Odeslat do Bluetooth - c:\program files (x86)\Intel\Bluetooth\btSendToObject.htm
TCP: DhcpNameServer = 10.0.0.100 10.0.0.200
TCP: Interfaces\{71455945-BABD-4FB1-B236-685344ED7763}: NameServer = 8.8.8.8
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - c:\users\czech_000\AppData\Roaming\Mozilla\Firefox\Profiles\qtewduse.default-1376041014175\
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-SynLenovoGestureMgr - d:\program files (x86)\Synaptics\SynTP\SynLenovoGestureMgr.exe
.
.
Binary file temp00 matches
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Jiné spuštené procesy ------------------------
.
d:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
d:\program files (x86)\Garena Plus\ggdllhost.exe
c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
.
**************************************************************************
.
Celkový čas: 2014-06-26 12:27:47 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-06-26 10:27
.
Před spuštěním: 86 042 955 776 bytes free
Po spuštění: 87 029 747 712 bytes free
.
- - End Of File - - 437E84BE0F8C78C089A1E61A305DA658
PHP, Nette, MySQL, C#, TypeScript, Python
IntelliJ Idea, Docker, Opera browser, Linux Mint
iPhone XS
Raspberry PI 3 (KODI, Raspbian)
XBox One S, PS 4, nVidia GeForce NOW

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Nejdou zabíjet procesy

Příspěvekod jaro3 » 27 čer 2014 09:39

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

@echo off
del /q /a /f %systemroot%\system32\drivers\etc\hosts 2>nul
echo 127.0.0.1 localhost>>%systemroot%\system32\drivers\etc\hosts
exit

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:název souboru, zde napiš: FixHosts.bat
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.
Poklepáním na soubor ho spusť.

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB nebo externí disky z počítače před spuštěním tohoto programu.
Spusť RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- Počkej, až Prescan dokončí práci...
- Počkej, dokud status okno zobrazuje "Prohledat "

- V záložkách (Registry , Tasks , Web Browser apod.) vše zatrhni (dej zatržítka)

- Klikni na "Smazat"
- Počkej, dokud Status box zobrazuje " Mazání dokončeno "
- Klikni na "Zpráva " a zkopíruj a vlož obsah té zprávy prosím sem. Log je možno nalézt v RKreport [číslo]. txt na ploše.
- Zavři RogueKiller

Vypni rez. ochranu u antiviru a antispywaru,příp. firewall..

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

Folder::
c:\program files (x86)\Skype\Updater

DirLook::
c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69

Driver::
SkypeUpdate

DDS::
uInternet Settings,ProxyOverride = <local>

RegLock::
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000



Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Stáhni si CrystalDiskInfo
Spusť program a klikni na Úpravy-Kopírovat. Poté sem vlož pomocí Ctrl+V obsah logu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
CZechBoY
Master Level 9.5
Master Level 9.5
Příspěvky: 8813
Registrován: srpen 08
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Nejdou zabíjet procesy

Příspěvekod CZechBoY » 28 čer 2014 12:26

RogueKiller V9.1.0.0 (x64) [Jun 23 2014] by Adlice Software
mail : http://www.adlice.com/contact/
Podpora : http://forum.adlice.com
Webové stránky : http://www.adlice.com/softwares/roguekiller/
: http://www.adlice.com

Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno v : Normální režim
Uživatel : czech_000 [Práva správce]
Mód : Odebrat -- Datum : 06/28/2014 12:24:58

¤¤¤ Škodlivé procesy: : 1 ¤¤¤
[Suspicious.Path] GameRanger.exe -- C:\Users\czech_000\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe[7] -> SMAZÁNO [TermThr]

¤¤¤ ¤¤¤ Záznamy Registrů: : 22 ¤¤¤
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\giveio -> VYMAZÁNO
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\giveio -> VYMAZÁNO
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.100 10.0.0.200 -> NAHRAZENO ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 10.0.0.100 10.0.0.200 -> NAHRAZENO ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{71455945-BABD-4FB1-B236-685344ED7763} | DhcpNameServer : 10.0.0.100 10.0.0.200 -> NAHRAZENO ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{71455945-BABD-4FB1-B236-685344ED7763} | DhcpNameServer : 10.0.0.100 10.0.0.200 -> NAHRAZENO ()
[PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> VYMAZÁNO
[PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 -> ERROR [2]
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-2911345036-808393445-1753524052-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-2911345036-808393445-1753524052-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-2911345036-808393445-1753524052-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-2911345036-808393445-1753524052-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-2911345036-808393445-1753524052-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-2911345036-808393445-1753524052-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-2911345036-808393445-1753524052-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-2911345036-808393445-1753524052-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] (X64) HKEY_USERS\S-1-5-21-2911345036-808393445-1753524052-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-2911345036-808393445-1753524052-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {645FF040-5081-101B-9F08-00AA002F954E} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-2911345036-808393445-1753524052-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> NAHRAZENO (0)
[PUM.DesktopIcons] (X86) HKEY_USERS\S-1-5-21-2911345036-808393445-1753524052-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> NAHRAZENO (0)

¤¤¤ naplánované úlohy : 0 ¤¤¤

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 25 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 localhost -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 live.rads.msn.com -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ads1.msn.com -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 static.2mdn.net -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 g.msn.com -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 a.ads2.msads.net -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 b.ads2.msads.net -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ad.doubleclick.net -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ac3.msn.com -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 rad.msn.com -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 msntest.serving-sys.com -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 bs.serving-sys.com -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 flex.msn.com -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 ec.atdmt.com -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 cdn.atdmt.com -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 db3aqu.atdmt.com -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 cds26.ams9.msecn.net -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 sO.2mdn.net -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 aka-cdn-ns.adtech.de -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 secure.flashtalking.com -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 adnexus.net -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 adnxs.com -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 *.rad.msn.com -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 *.msads.net -> VYMAZÁNO
[C:\Windows\System32\drivers\etc\hosts] 127.0.0.1 *.msecn.net -> VYMAZÁNO

¤¤¤ Antirootkit : 0 ¤¤¤

¤¤¤ Webové prohlížeče : 20 ¤¤¤
[FIREFX:Addon] qtewduse.default-1376041014175 : Adblock Plus [{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}] -> VYMAZÁNO
[FIREFX:Addon] qtewduse.default-1376041014175 : Web Metrics Framework [wmf@javascriptrules.com] -> VYMAZÁNO
[FIREFX:Addon] qtewduse.default-1376041014175 : Good Website Inspector [gwif-quality@goodwebsiteinspector.com] -> VYMAZÁNO
[FIREFX:Addon] qtewduse.default-1376041014175 : Firefinder for Firebug [firefinder@robertnyman.com] -> VYMAZÁNO
[FIREFX:Addon] qtewduse.default-1376041014175 : FireGestures [firegestures@xuldev.org] -> VYMAZÁNO
[FIREFX:Addon] qtewduse.default-1376041014175 : Firebug [firebug@software.joehewitt.com] -> VYMAZÁNO
[FIREFX:Addon] qtewduse.default-1376041014175 : NoRedirect [{c1970c0d-dbe6-4d91-804f-c9c0de643a57}] -> VYMAZÁNO
[FIREFX:Addon] qtewduse.default-1376041014175 : Dust-Me Selectors [{3c6e1eed-a07e-4c80-9cf3-66ea0bf40b37}] -> VYMAZÁNO
[FIREFX:Addon] qtewduse.default-1376041014175 : YSlow [yslow@yahoo-inc.com] -> VYMAZÁNO
[FIREFX:Addon] qtewduse.default-1376041014175 : Mozilla Firefox hotfix [firefox-hotfix@mozilla.org] -> VYMAZÁNO
[FIREFX:Addon] qtewduse.default-1376041014175 : RescueTime for Firefox [rescuetime_firefox@rescuetime.com] -> VYMAZÁNO
[FIREFX:Addon] qtewduse.default-1376041014175 : Page Speed [{e3f6c2cc-d8db-498c-af6c-499fb211db97}] -> VYMAZÁNO
[CHROME:Addon] Default : Google Docs [aohghmighlieiainnegkcijnfilokake] -> VYMAZÁNO
[CHROME:Addon] Default : Google Drive [apdfllckaahabafndbhieahigkjlhalf] -> ERROR [2]
[CHROME:Addon] Default : RescueTime for Chrome™ & ChromeOS™ [bdakmnplckeopfghnlpocafcepegjeap] -> ERROR [2]
[CHROME:Addon] Default : YouTube [blpcfgokakmgnkcojhhkbfbldkacnbeo] -> ERROR [2]
[CHROME:Addon] Default : Google Search [coobgpohoikkiipiblmjeljniedjpjpf] -> ERROR [2]
[CHROME:Addon] Default : Tampermonkey [dhdgffkkebhmkfjojejmpbldmpobfkfo] -> ERROR [2]
[CHROME:Addon] Default : Google Wallet [nmmhkkegccagdldgiimedpiccmgmieda] -> ERROR [2]
[CHROME:Addon] Default : Gmail [pjkljhegncpnkpknbcohdijeoejaedia] -> ERROR [2]

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: ST1000LM024 HN-M101MBB +++++
--- User ---
[MBR] af2d5d26254f379ef01a9d18b0ba1e96
[BSP] e5564d3a591cf8403f708aa9e7a52e9a : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 350 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 718848 | Size: 150775 MB
2 - [XXXXXX] COMPAQ (0x12) [VISIBLE] Offset (sectors): 309506048 | Size: 1500 MB
3 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 312578048 | Size: 801242 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_SCN_06282014_115409.log - RKreport_SCN_06282014_122315.log
PHP, Nette, MySQL, C#, TypeScript, Python
IntelliJ Idea, Docker, Opera browser, Linux Mint
iPhone XS
Raspberry PI 3 (KODI, Raspbian)
XBox One S, PS 4, nVidia GeForce NOW

Uživatelský avatar
CZechBoY
Master Level 9.5
Master Level 9.5
Příspěvky: 8813
Registrován: srpen 08
Bydliště: Brno
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: Nejdou zabíjet procesy

Příspěvekod CZechBoY » 28 čer 2014 14:16

ComboFix 14-06-27.01 - czech_000 . 06. 2014 12:32:36.2.4 - x64
Microsoft Windows 8 Pro 6.2.9200.0.1250.420.1029.18.3956.440 [GMT 2:00]
Spuštěný z: c:\users\czech_000\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\czech_000\Desktop\CFScript.txt
AV: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Skype\Updater
c:\program files (x86)\Skype\Updater\Updater.dll
c:\program files (x86)\Skype\Updater\Updater.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2014-05-28 do 2014-06-28 )))))))))))))))))))))))))))))))
.
.
2014-06-28 10:50 . 2014-06-28 10:50 -------- d-----w- c:\users\Public\AppData\Local\temp
2014-06-28 10:50 . 2014-06-28 10:50 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-06-28 09:39 . 2014-06-28 09:39 -------- d-----w- c:\programdata\RogueKiller
2014-06-21 12:41 . 2014-06-21 13:10 -------- d-----w- c:\users\czech_000\AppData\Roaming\Audacity
2014-06-21 11:22 . 2014-06-21 11:22 -------- d-----w- c:\windows\SysWow64\NV
2014-06-21 11:22 . 2014-06-21 11:22 -------- d-----w- c:\windows\system32\NV
2014-06-21 11:03 . 2014-05-29 23:07 1291232 ----a-w- c:\windows\SysWow64\nvspbridge.dll
2014-06-21 11:03 . 2014-05-29 23:07 1715176 ----a-w- c:\windows\system32\nvspbridge64.dll
2014-06-21 11:02 . 2014-06-21 11:19 -------- d-----w- c:\windows\LastGood.Tmp
2014-06-21 11:02 . 2014-03-31 16:42 40392 ----a-w- c:\windows\system32\drivers\nvvad64v.sys
2014-06-21 11:02 . 2014-03-31 16:42 37320 ----a-w- c:\windows\system32\nvaudcap64v.dll
2014-06-21 11:02 . 2014-03-31 16:42 34760 ----a-w- c:\windows\SysWow64\nvaudcap32v.dll
2014-06-18 08:50 . 2014-06-25 21:59 -------- d-----w- c:\users\czech_000\AppData\Local\Adobe
2014-06-16 18:54 . 2014-06-16 22:21 -------- d-----w- c:\users\czech_000\AppData\Roaming\TS3Client
2014-06-14 10:37 . 2014-05-24 02:46 3958784 ----a-w- c:\windows\system32\jscript9.dll
2014-06-14 10:37 . 2014-05-24 02:46 2650112 ----a-w- c:\windows\system32\iertutil.dll
2014-06-14 10:37 . 2014-05-24 01:25 2862080 ----a-w- c:\windows\SysWow64\jscript9.dll
2014-06-14 10:36 . 2014-03-07 00:47 1419264 ----a-w- c:\windows\SysWow64\msxml3.dll
2014-06-14 10:36 . 2014-03-07 00:08 1845760 ----a-w- c:\windows\system32\msxml3.dll
2014-06-14 10:36 . 2014-04-03 11:22 2233176 ----a-w- c:\windows\system32\drivers\tcpip.sys
2014-06-13 22:56 . 2014-06-16 12:45 -------- d-----w- d:\program files (x86)\rFactor
2014-06-09 21:00 . 2014-06-09 21:00 -------- d-----w- d:\program files (x86)\Anki
2014-06-04 08:17 . 2014-06-04 08:17 -------- d-----w- d:\program files (x86)\iTunes
2014-06-04 08:17 . 2014-06-04 08:17 -------- d-----w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-06-28 10:38 . 2014-04-21 15:27 122584 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-06-14 13:29 . 2013-07-14 23:28 95414520 ----a-w- c:\windows\system32\MRT.exe
2014-05-31 05:16 . 2012-07-26 08:14 703992 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-05-31 05:16 . 2012-07-26 08:14 105464 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-05-29 23:07 . 2013-10-30 09:27 1122312 ----a-w- c:\windows\SysWow64\nvspcap.dll
2014-05-29 23:07 . 2013-10-30 09:27 1279480 ----a-w- c:\windows\system32\nvspcap64.dll
2014-05-20 02:44 . 2013-07-14 22:41 952952 ----a-w- c:\windows\system32\nvumdshimx.dll
2014-05-20 02:44 . 2013-07-14 22:41 837056 ----a-w- c:\windows\SysWow64\nvumdshim.dll
2014-05-20 02:44 . 2013-07-14 22:41 3109248 ----a-w- c:\windows\system32\nvapi64.dll
2014-05-20 02:44 . 2013-07-14 22:41 2730208 ----a-w- c:\windows\SysWow64\nvapi.dll
2014-05-20 02:44 . 2013-07-14 22:41 166568 ----a-w- c:\windows\system32\nvinitx.dll
2014-05-20 02:44 . 2013-07-14 22:41 146480 ----a-w- c:\windows\SysWow64\nvinit.dll
2014-05-20 01:25 . 2013-07-14 22:43 6769096 ----a-w- c:\windows\system32\nvcpl.dll
2014-05-20 01:25 . 2013-07-14 22:43 3514144 ----a-w- c:\windows\system32\nvsvc64.dll
2014-05-20 01:25 . 2013-07-14 22:43 927520 ----a-w- c:\windows\system32\nvvsvc.exe
2014-05-20 01:25 . 2013-07-14 22:43 76064 ----a-w- c:\windows\system32\nv3dappshextr.dll
2014-05-20 01:25 . 2013-07-14 22:43 62808 ----a-w- c:\windows\system32\nvshext.dll
2014-05-20 01:25 . 2013-07-14 22:43 387528 ----a-w- c:\windows\system32\nvmctray.dll
2014-05-20 01:25 . 2013-07-14 22:43 2560968 ----a-w- c:\windows\system32\nvsvcr.dll
2014-05-20 01:25 . 2013-07-14 22:43 1078616 ----a-w- c:\windows\system32\nv3dappshext.dll
2014-05-20 01:25 . 2013-07-14 22:42 610592 ----a-w- c:\windows\SysWow64\oemdspif.dll
2014-05-14 23:49 . 2013-07-14 22:43 3774821 ----a-w- c:\windows\system32\nvcoproc.bin
2014-05-13 17:56 . 2014-04-28 16:56 17938608 ----a-w- c:\windows\SysWow64\FlashPlayerInstaller.exe
2014-05-12 05:26 . 2014-04-21 15:27 64216 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-05-12 05:26 . 2014-01-28 20:03 91352 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-05-12 05:25 . 2013-07-28 10:13 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-04-25 00:16 . 2014-04-25 00:16 1070232 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2014-04-19 09:39 . 2014-05-06 09:16 628024 ----a-w- c:\windows\system32\NotificationUI.exe
2014-04-19 08:45 . 2014-05-06 09:16 693760 ----a-w- c:\windows\system32\WSShared.dll
2014-04-19 08:45 . 2014-05-06 09:16 163840 ----a-w- c:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-19 06:57 . 2014-05-06 09:16 566784 ----a-w- c:\windows\SysWow64\WSShared.dll
2014-04-19 06:57 . 2014-05-06 09:16 124928 ----a-w- c:\windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-15 08:46 . 2014-04-15 08:46 46136 ---ha-w- c:\windows\system32\drivers\Hamdrv.sys
2014-04-14 18:13 . 2014-05-19 20:20 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-04-12 09:27 . 2014-05-23 08:18 172888 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2014-04-12 09:10 . 2014-05-23 08:18 578048 ----a-w- c:\windows\system32\winlogon.exe
2014-04-12 09:09 . 2014-05-23 08:18 208896 ----a-w- c:\windows\system32\wdigest.dll
2014-04-12 09:09 . 2014-05-23 08:18 1043968 ----a-w- c:\windows\system32\usercpl.dll
2014-04-12 09:09 . 2014-05-23 08:18 94720 ----a-w- c:\windows\system32\TSpkg.dll
2014-04-12 09:09 . 2014-05-23 08:18 588288 ----a-w- c:\windows\system32\SHCore.dll
2014-04-12 09:08 . 2014-05-23 08:18 318464 ----a-w- c:\windows\system32\msv1_0.dll
2014-04-12 09:08 . 2014-05-23 08:18 1281536 ----a-w- c:\windows\system32\lsasrv.dll
2014-04-12 09:08 . 2014-05-23 08:18 439808 ----a-w- c:\windows\system32\lsm.dll
2014-04-12 09:08 . 2014-05-23 08:18 827904 ----a-w- c:\windows\system32\kerberos.dll
2014-04-12 09:07 . 2014-05-23 08:18 20480 ----a-w- c:\windows\system32\credssp.dll
2014-04-12 07:23 . 2014-05-23 08:18 178688 ----a-w- c:\windows\SysWow64\wdigest.dll
2014-04-12 07:23 . 2014-05-23 08:18 961536 ----a-w- c:\windows\SysWow64\usercpl.dll
2014-04-12 07:23 . 2014-05-23 08:18 76800 ----a-w- c:\windows\SysWow64\TSpkg.dll
2014-04-12 07:23 . 2014-05-23 08:18 452608 ----a-w- c:\windows\SysWow64\SHCore.dll
2014-04-12 07:23 . 2014-05-23 08:18 273920 ----a-w- c:\windows\SysWow64\msv1_0.dll
2014-04-12 07:22 . 2014-05-23 08:18 666624 ----a-w- c:\windows\SysWow64\kerberos.dll
2014-04-12 07:22 . 2014-05-23 08:18 17408 ----a-w- c:\windows\SysWow64\credssp.dll
2014-04-12 06:58 . 2014-05-23 08:18 14848 ----a-w- c:\windows\system32\workerdd.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69 ----
.
2014-06-04 08:17 . 2014-06-04 08:17 4842 ----a-w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\DIFxInstallLog.txt
2012-08-21 11:01 . 2012-08-21 11:01 1977816 ----a-w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\GEARDIFx.exe
2012-08-21 11:01 . 2012-08-21 11:01 519048 ----a-w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\DIFxAPI.dll
2012-08-21 11:01 . 2012-08-21 11:01 131544 ----a-w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\DifXInst64.exe
2012-08-21 11:01 . 2012-08-21 11:01 106928 ----a-w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\GEARAspi.dll
2012-08-21 11:01 . 2012-08-21 11:01 125872 ----a-w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\GEARAspi64.dll
2012-08-21 11:01 . 2012-08-21 11:01 2561 ----a-w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\GEARAspiWDM.inf
2012-08-21 11:01 . 2012-08-21 11:01 7638 ----a-w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\gearaspiwdmx64.cat
2012-08-21 11:01 . 2012-08-21 11:01 33240 ----a-w- c:\programdata\34BE82C4-E596-4e99-A191-52C6199EBF69\x64\x64\GEARAspiWDM.sys
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-18 08:20 222832 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-18 08:20 222832 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-18 08:20 222832 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2014-05-14 06:15 1730264 ----a-w- d:\program files (x86)\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2014-05-14 06:15 1730264 ----a-w- d:\program files (x86)\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2014-05-14 06:15 1730264 ----a-w- d:\program files (x86)\MICROS~1\Office15\GROOVEEX.DLL
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2014-05-08 21444224]
"GarenaPlus"="d:\program files (x86)\Garena Plus\GarenaMessenger.exe" [2014-04-29 9936176]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe" [2012-07-16 56128]
"LogMeIn Hamachi Ui"="d:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2014-04-15 3814736]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\
RescueTime.lnk - d:\program files (x86)\RescueTime\RescueTime.exe [2014-4-2 3343360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll
.
R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);c:\windows\system32\drivers\sfdrv01a.sys;c:\windows\SYSNATIVE\drivers\sfdrv01a.sys [x]
R3 AcuWVSSchedulerv8;Acunetix WVS Scheduler v8;d:\program files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe;d:\program files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe [x]
R3 anvsnddrv;AnvSoft Virtual Sound Device;c:\windows\system32\drivers\anvsnddrv.sys;c:\windows\SYSNATIVE\drivers\anvsnddrv.sys [x]
R3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [x]
R3 GGSAFERDriver;GGSAFER Driver;d:\program files (x86)\Garena Plus\Room\safedrv.sys;d:\program files (x86)\Garena Plus\Room\safedrv.sys [x]
R3 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;d:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;d:\program files\Intel\WiFi\bin\PanDhcpDns.exe;d:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 NETwNe64;Ovladač adaptéru řady Intel(R) Wireless WiFi Link 5000 pro systém Windows 8 64 Bit;c:\windows\system32\DRIVERS\NETwew00.sys;c:\windows\SYSNATIVE\DRIVERS\NETwew00.sys [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUVStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUVStor.sys [x]
R3 SolutoRemoteService;Soluto Remote Service;d:\program files\Soluto\SolutoRemoteService.exe;d:\program files\Soluto\SolutoRemoteService.exe [x]
R3 Speechsrv;Glasovne poruke;d:\program files (x86)\LAN Voice Chat\Speechs.exe;d:\program files (x86)\LAN Voice Chat\Speechs.exe [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 SuperIO;Lenovo ASD HWM Driver;c:\windows\System32\drivers\spio.sys;c:\windows\SYSNATIVE\drivers\spio.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys;c:\windows\SYSNATIVE\DRIVERS\tap0901t.sys [x]
R3 Te.Service;Te.Service;c:\program files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe;c:\program files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [x]
R3 TunngleService;TunngleService;d:\program files (x86)\Tunngle\TnglCtrl.exe;d:\program files (x86)\Tunngle\TnglCtrl.exe [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
R3 VBoxUSB;VirtualBox USB;c:\windows\System32\Drivers\VBoxUSB.sys;c:\windows\SYSNATIVE\Drivers\VBoxUSB.sys [x]
R3 vmicheartbeat;Služba prezenčního signálu technologie Hyper-V;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
R3 VsEtwService120;Visual Studio ETW Event Collection Service;d:\program files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe;d:\program files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [x]
S0 fltsrv;Acronis Storage Filter Management;c:\windows\system32\DRIVERS\fltsrv.sys;c:\windows\SYSNATIVE\DRIVERS\fltsrv.sys [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys;c:\windows\SYSNATIVE\DRIVERS\LhdX64.sys [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S0 Soluto;Soluto;c:\windows\system32\DRIVERS\Soluto.sys;c:\windows\SYSNATIVE\DRIVERS\Soluto.sys [x]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxDrv.sys [x]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x]
S2 Bluetooth Device Monitor;Bluetooth Device Monitor;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe;c:\program files (x86)\Intel\Bluetooth\devmonsrv.exe [x]
S2 Bluetooth OBEX Service;Bluetooth OBEX Service;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe;c:\program files (x86)\Intel\Bluetooth\obexsrv.exe [x]
S2 IAStorDataMgrSvc;Úložná technologie Intel® Rapid;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;Intel(R) Wireless Bluetooth(R) 4.0 Radio Management;c:\program files (x86)\Intel\Bluetooth\ibtrksrv.exe;c:\program files (x86)\Intel\Bluetooth\ibtrksrv.exe [x]
S2 MBAMService;MBAMService;d:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;d:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;d:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;d:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 SolutoLauncherService;Soluto Launcher Service;d:\program files\Soluto\SolutoLauncherService.exe;d:\program files\Soluto\SolutoLauncherService.exe [x]
S2 SolutoService;Soluto PCGenome Core Service;d:\program files\Soluto\SolutoService.exe;d:\program files\Soluto\SolutoService.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 ZeroConfigService;Intel(R) PROSet/Wireless Zero Configuration Service;d:\program files\Intel\WiFi\bin\ZeroConfigService.exe;d:\program files\Intel\WiFi\bin\ZeroConfigService.exe [x]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\System32\drivers\AcpiVpc.sys;c:\windows\SYSNATIVE\drivers\AcpiVpc.sys [x]
S3 BthLEEnum;Ovladač úspory energie technologie Bluetooth;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 btmaux;Intel Bluetooth Auxiliary Service;c:\windows\system32\DRIVERS\btmaux.sys;c:\windows\SYSNATIVE\DRIVERS\btmaux.sys [x]
S3 btmhsf;btmhsf;c:\windows\system32\DRIVERS\btmhsf.sys;c:\windows\SYSNATIVE\DRIVERS\btmhsf.sys [x]
S3 ibtfltcoex;ibtfltcoex;c:\windows\system32\DRIVERS\iBtFltCoex.sys;c:\windows\SYSNATIVE\DRIVERS\iBtFltCoex.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
S3 NvStreamKms;NvStreamKms;d:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;d:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RTL8168;Realtek 8168 NT Driver;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
S3 rtsuvc;Lenovo EasyCamera;c:\windows\system32\DRIVERS\rtsuvc.sys;c:\windows\SYSNATIVE\DRIVERS\rtsuvc.sys [x]
S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-04-25 08:44 1078088 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.131\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2014-06-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-15 10:45]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2013-08-18 08:20 261744 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2013-08-18 08:20 261744 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2013-08-18 08:20 261744 ----a-w- c:\users\czech_000\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro1 (ErrorConflict)]
@="{8BA85C75-763B-4103-94EB-9470F12FE0F7}"
[HKEY_CLASSES_ROOT\CLSID\{8BA85C75-763B-4103-94EB-9470F12FE0F7}]
2014-05-14 06:18 2335960 ----a-w- d:\program files\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro2 (SyncInProgress)]
@="{CD55129A-B1A1-438E-A425-CEBC7DC684EE}"
[HKEY_CLASSES_ROOT\CLSID\{CD55129A-B1A1-438E-A425-CEBC7DC684EE}]
2014-05-14 06:18 2335960 ----a-w- d:\program files\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrivePro3 (InSync)]
@="{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}"
[HKEY_CLASSES_ROOT\CLSID\{E768CD3B-BDDC-436D-9C13-E1B39CA257B1}]
2014-05-14 06:18 2335960 ----a-w- d:\program files\MICROS~2\Office15\GROOVEEX.DLL
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-12-19 172168]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-12-19 441992]
"SynLenovoGestureMgr"="d:\program files (x86)\Synaptics\SynTP\SynLenovoGestureMgr.exe" [BU]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-05-29 2352072]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2013-07-14 17080376]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2013-07-14 191544]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-05-29 1279480]
"BTMTrayAgent"="c:\program files (x86)\Intel\Bluetooth\btmshellex.dll" [2013-09-19 7818040]
"Soluto"="d:\program files\soluto\soluto.exe" [2013-08-17 1252896]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\nvinitx.dll c:\windows\System32\nvinitx.dll
.
------- Doplňkový sken -------
.
uLocal Page = %SystemRoot%\system32\blank.htm
uStart Page = about:blank
mLocal Page = c:\windows\SYSTEM32\blank.htm
IE: E&xport to Microsoft Excel - d:\program files (x86)\MICROS~1\Office15\EXCEL.EXE/3000
IE: Inspect Element with DebugBar - d:\program files (x86)\Core Services\DebugBar\DebugInfoBar.dll/247
IE: Odeslat do Bluetooth - c:\program files (x86)\Intel\Bluetooth\btSendToObject.htm
TCP: DhcpNameServer = 10.0.0.100 10.0.0.200
TCP: Interfaces\{71455945-BABD-4FB1-B236-685344ED7763}: NameServer = 8.8.8.8
Filter: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
FF - ProfilePath - c:\users\czech_000\AppData\Roaming\Mozilla\Firefox\Profiles\qtewduse.default-1376041014175\
.
Binary file temp00 matches
.
------------------------ Jiné spuštené procesy ------------------------
.
d:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
d:\program files (x86)\Garena Plus\ggdllhost.exe
c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
.
**************************************************************************
.
Celkový čas: 2014-06-28 13:04:58 - počítač byl restartován
ComboFix-quarantined-files.txt 2014-06-28 11:04
ComboFix2.txt 2014-06-26 10:27
.
Před spuštěním: 87 901 167 616 bytes free
Po spuštění: 87 530 426 368 bytes free
.
- - End Of File - - 0089685116D2701E2B125F0902450E6C














Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:17:26, on 28. 6. 2014
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
D:\Program Files (x86)\RescueTime\RescueTime.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
D:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
D:\Program Files (x86)\Opera\22.0.1471.70\opera_crashreporter.exe
D:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
D:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
D:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
D:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
D:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
D:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
D:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
D:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
D:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
D:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
D:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
D:\Program Files (x86)\Opera\22.0.1471.70\opera.exe
D:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - D:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Microsoft Web Test Recorder 12.0 Helper - {432dd630-7e03-4c97-9d62-b99f52df4fc2} - D:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O2 - BHO: DebugBar BHO - {69FC0024-10EB-480A-BBF2-3BF4E78E17B1} - D:\Program Files (x86)\Core Services\DebugBar\DebugInfoBar.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - D:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - D:\Program Files (x86)\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [GarenaPlus] "D:\Program Files (x86)\Garena Plus\GarenaMessenger.exe" -autolaunch
O4 - Global Startup: RescueTime.lnk = D:\Program Files (x86)\RescueTime\RescueTime.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\Program Files (x86)\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Inspect Element with DebugBar - res://D:\Program Files (x86)\Core Services\DebugBar\DebugInfoBar.dll/247
O8 - Extra context menu item: Odeslat do Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - D:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - D:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: Odeslat do Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (file missing) (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - ESC Trusted Zone: http://*.connectify.me
O15 - ESC Trusted Zone: http://*.fastspring.com
O15 - ESC Trusted Zone: http://*.connectify.me (HKLM)
O15 - ESC Trusted Zone: http://*.fastspring.com (HKLM)
O17 - HKLM\System\CCS\Services\Tcpip\..\{71455945-BABD-4FB1-B236-685344ED7763}: NameServer = 8.8.8.8
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - D:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll
O23 - Service: Acunetix WVS Scheduler v8 (AcuWVSSchedulerv8) - Unknown owner - D:\Program Files (x86)\Acunetix\Web Vulnerability Scanner 8\WVSScheduler.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - D:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: LogMeIn Hamachi Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Úložná technologie Intel® Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) Wireless Bluetooth(R) 4.0 Radio Management - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - D:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - D:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - D:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Unknown owner - C:\Windows\system32\sfrem01.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Soluto Launcher Service (SolutoLauncherService) - Soluto - D:\Program Files\Soluto\SolutoLauncherService.exe
O23 - Service: Soluto Remote Service (SolutoRemoteService) - GlavSoft LLC. - D:\Program Files\Soluto\SolutoRemoteService.exe
O23 - Service: Soluto PCGenome Core Service (SolutoService) - Soluto - D:\Program Files\Soluto\SolutoService.exe
O23 - Service: Glasovne poruke (Speechsrv) - Unknown owner - D:\Program Files (x86)\LAN Voice Chat\Speechs.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Aktivátor Správce výběru OS Acronis (Správce výběru OS) - Unknown owner - D:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TeamViewer 9 (TeamViewer9) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
O23 - Service: TunngleService - Tunngle.net GmbH - D:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - D:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - D:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - D:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 12628 bytes
PHP, Nette, MySQL, C#, TypeScript, Python
IntelliJ Idea, Docker, Opera browser, Linux Mint
iPhone XS
Raspberry PI 3 (KODI, Raspbian)
XBox One S, PS 4, nVidia GeForce NOW

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10645
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž
Stav:
Offline

Re: Nejdou zabíjet procesy

Příspěvekod Orcus » 28 čer 2014 18:49

ComboFix se odinstaluje takto:
Start-Spustit a zadej ComboFix /Uninstall

====================================================

Vyčisti systém CCleanerem

====================================================

Stáhni si zde DelFix
http://general-changelog-team.fr/fr/dow ... e/9-delfix

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7 a 8, musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore) .
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci.

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem. Jinak je zpráva zde:
v C: \ DelFix.txt

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 95 hostů