part 2:
>Stealth
==============================================
0x83799000 WARNING: suspicious driver modification [atapi.sys::0x860F1AEA]
0x66550000 Hidden Image-->System.Runtime.Serialization.ni.dll [ EPROCESS 0x85A8FD40 ] PID: 4068, 1196032 bytes
0x66550000 Hidden Image-->System.Runtime.Serialization.ni.dll [ EPROCESS 0x87F57030 ] PID: 5988, 1196032 bytes
0x66520000 Hidden Image-->System.ServiceModel.Web.ni.dll [ EPROCESS 0x85A8FD40 ] PID: 4068, 143360 bytes
0x66520000 Hidden Image-->System.ServiceModel.Web.ni.dll [ EPROCESS 0x87F57030 ] PID: 5988, 143360 bytes
0x66090000 Hidden Image-->System.Core.ni.dll [ EPROCESS 0x85A8FD40 ] PID: 4068, 2375680 bytes
0x66090000 Hidden Image-->System.Core.ni.dll [ EPROCESS 0x87F57030 ] PID: 5988, 2375680 bytes
0x00EB0000 Hidden Image-->Interop.HPQWMIEXLib.dll [ EPROCESS 0x87B9C030 ] PID: 3052, 28672 bytes
0x00FA0000 Hidden Image-->Interop.HPQTOASTERLib.dll [ EPROCESS 0x87B9C030 ] PID: 3052, 28672 bytes
0x8EA96000 WARNING: Virus alike driver modification [WFPLWF.SYS], 28672 bytes
0x00A50000 Hidden Image-->HPWAMain.resources.dll [ EPROCESS 0x87B9C030 ] PID: 3052, 36864 bytes
0x68600000 Hidden Image-->System.Windows.Browser.ni.dll [ EPROCESS 0x85A8FD40 ] PID: 4068, 380928 bytes
0x68600000 Hidden Image-->System.Windows.Browser.ni.dll [ EPROCESS 0x87F57030 ] PID: 5988, 380928 bytes
0x66680000 Hidden Image-->System.Windows.ni.dll [ EPROCESS 0x85A8FD40 ] PID: 4068, 4476928 bytes
0x66680000 Hidden Image-->System.Windows.ni.dll [ EPROCESS 0x87F57030 ] PID: 5988, 4476928 bytes
0x9A906F2E Unknown thread object [ ETHREAD 0x85904020 ] , 600 bytes
0x67000000 Hidden Image-->mscorlib.ni.dll [ EPROCESS 0x85A8FD40 ] PID: 4068, 6197248 bytes
0x67000000 Hidden Image-->mscorlib.ni.dll [ EPROCESS 0x87F57030 ] PID: 5988, 6197248 bytes
0x662E0000 Hidden Image-->System.Net.ni.dll [ EPROCESS 0x85A8FD40 ] PID: 4068, 659456 bytes
0x662E0000 Hidden Image-->System.Net.ni.dll [ EPROCESS 0x87F57030 ] PID: 5988, 659456 bytes
0x66C10000 Hidden Image-->System.ni.dll [ EPROCESS 0x85A8FD40 ] PID: 4068, 671744 bytes
0x66C10000 Hidden Image-->System.ni.dll [ EPROCESS 0x87F57030 ] PID: 5988, 671744 bytes
0x65FC0000 Hidden Image-->System.Xml.ni.dll [ EPROCESS 0x85A8FD40 ] PID: 4068, 847872 bytes
0x65FC0000 Hidden Image-->System.Xml.ni.dll [ EPROCESS 0x87F57030 ] PID: 5988, 847872 bytes
==============================================
>Files
==============================================
!-->[Hidden] C:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat::$DATA
!-->[Hidden] C:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat::$DATA
!-->[Hidden] C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_svchost.exe_def2ddcebc21279351a5983e1239f72ebd1abc7_1341075c\Report.wer
!-->[Hidden] C:\ProgramData\Real\setup\config.ini::$DATA
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1KKICUN7\rssCAP1BFWM
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\216YWIJR\rssCAQ0SMI7
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ARX3PAVM\QuoteRequestCAQFQQAN.txt
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q586RQXI\QuoteRequestCA3BEAIV.txt
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q586RQXI\rssCA07HVYQ
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\2Z9LS7WO\ppEY[2].txt
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\5WL4I0HZ\18747993[1].rss
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Temp\Low\415303181942878824.tmp
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Temp\~DF057A41767851A83E.TMP::$DATA
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Temp\~DF2BA19FB07840639F.TMP::$DATA
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Temp\~DF35891B96A58D509D.TMP::$DATA
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Temp\~DF8EC5A66E3A0AE9F7.TMP::$DATA
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Temp\~DFC3258C05808A39B9.TMP::$DATA
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Temp\~DFDEAC9CA4825F9E8B.TMP::$DATA
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Temp\~DFF6228E962D63618A.TMP::$DATA
!-->[Hidden] C:\Users\Gypsy\AppData\Local\Temp\~DFFDF634C016B4B058.TMP::$DATA
!-->[Hidden] C:\Users\Gypsy\Pictures\actions\mw_dreamy_glow+cleanup_12_07.atn::$DATA
!-->[Hidden] C:\Users\Gypsy\Pictures\actions\mw_dreamy_glow+cleanup_12_07.atn:Zone.Identifier:$DATA
!-->[Hidden] C:\Users\Gypsy\Pictures\actions\mw_dreamy_glow_11_06\__MACOSX\._mw_dreamy_glow_11_06::$DATA
!-->[Hidden] C:\Users\Gypsy\Pictures\actions\mw_dreamy_glow_11_06\__MACOSX\._mw_dreamy_glow_11_06:Zone.Identifier:$DATA
!-->[Hidden] C:\Users\Gypsy\Pictures\actions\mw_dreamy_glow_11_06\__MACOSX\mw_dreamy_glow_11_06\._.DS_Store::$DATA
!-->[Hidden] C:\Users\Gypsy\Pictures\actions\mw_dreamy_glow_11_06\__MACOSX\mw_dreamy_glow_11_06\._.DS_Store:Zone.Identifier:$DATA
!-->[Hidden] C:\Users\Gypsy\Pictures\actions\mw_dreamy_glow_11_06\__MACOSX\mw_dreamy_glow_11_06\._mw_dreamy_glow+cleanup_12_07.atn::$DATA
!-->[Hidden] C:\Users\Gypsy\Pictures\actions\mw_dreamy_glow_11_06\__MACOSX\mw_dreamy_glow_11_06\._mw_dreamy_glow+cleanup_12_07.atn:Zone.Identifier:$DATA
!-->[Hidden] C:\Users\Gypsy\Pictures\actions\mw_dreamy_glow_11_06\__MACOSX\mw_dreamy_glow_11_06\._Read_me_Loading_Actions.rtf::$DATA
!-->[Hidden] C:\Users\Gypsy\Pictures\actions\mw_dreamy_glow_11_06\__MACOSX\mw_dreamy_glow_11_06\._Read_me_Loading_Actions.rtf:Zone.Identifier:$DATA
!-->[Hidden] C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3LNM6IFB\goodnews;site=thegrio;sect=goodnews;!c=goodnews;pageid=383;tandomad=none;pm=1;dcopt=ist;pos=1;tile=1;sz=728x90,970x66;ord=767579324883[1]1]
==============================================
>Hooks
==============================================
Key object-->ParseProcedure, Type: Kernel Object [klmd.sys]
ntkrnlpa.exe+0x00222CF3, Type: Inline - RelativeJump 0x82C69CF3-->8EE67012 [aswSP.SYS]
ntkrnlpa.exe-->NtCreateSection, Type: Inline - RelativeJump 0x82C77D63-->8EE699D6 [aswSP.SYS]
ntkrnlpa.exe-->ObMakeTemporaryObject, Type: Inline - RelativeJump 0x82C4FFBF-->8EE655D4 [aswSP.SYS]
[1008]OUTLOOK.EXE-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C617B8-->00000000 [apphelp.dll]
[1008]OUTLOOK.EXE-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B611B8-->00000000 [apphelp.dll]
[1008]OUTLOOK.EXE-->kernel32.dll-->SetUnhandledExceptionFilter, Type: Inline - RelativeJump 0x763F3162-->00000000 [MSO.DLL]
[1008]OUTLOOK.EXE-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D114E0-->00000000 [apphelp.dll]
[1008]OUTLOOK.EXE-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x7120144C-->00000000 [apphelp.dll]
[1132]FlashUtil10i_ActiveX.exe-->user32.dll-->ChangeDisplaySettingsExA, Type: Inline - DirectJump 0x767081B7-->00000000 [unknown_code_page]
[1132]FlashUtil10i_ActiveX.exe-->user32.dll-->ChangeDisplaySettingsExW, Type: Inline - DirectJump 0x7672FA61-->00000000 [unknown_code_page]
[1132]FlashUtil10i_ActiveX.exe-->user32.dll-->SetForegroundWindow, Type: Inline - DirectJump 0x766ED3AE-->00000000 [unknown_code_page]
[1132]FlashUtil10i_ActiveX.exe-->user32.dll-->SetWindowPos, Type: Inline - DirectJump 0x766F3581-->00000000 [unknown_code_page]
[1304]rundll32.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C617B8-->00000000 [apphelp.dll]
[1304]rundll32.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B611B8-->00000000 [apphelp.dll]
[1304]rundll32.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D114E0-->00000000 [apphelp.dll]
[1304]rundll32.exe-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x7120144C-->00000000 [apphelp.dll]
[1608]AvastSvc.exe-->kernel32.dll-->SetUnhandledExceptionFilter, Type: Inline - PushRet 0x763F3162-->00000000 [unknown_code_page]
[1952]BDTUpdateService.exe-->advapi32.dll-->CreateServiceW, Type: IAT modification 0x0042C04C-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->advapi32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77C6178C-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->advapi32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77C617F0-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->advapi32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77C61848-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C617B8-->00000000 [apphelp.dll]
[1952]BDTUpdateService.exe-->advapi32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x77C61844-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->advapi32.dll-->RegCreateKeyExW, Type: IAT modification 0x0042C07C-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->advapi32.dll-->RegDeleteValueW, Type: IAT modification 0x0042C084-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->advapi32.dll-->RegOpenKeyExW, Type: IAT modification 0x0042C078-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->advapi32.dll-->RegSetValueExW, Type: IAT modification 0x0042C070-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->gdi32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77B61154-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->gdi32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77B611E0-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->gdi32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77B6118C-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B611B8-->00000000 [apphelp.dll]
[1952]BDTUpdateService.exe-->kernel32.dll-->CreateFileA, Type: IAT modification 0x0042C1B4-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->kernel32.dll-->CreateFileW, Type: IAT modification 0x0042C1D0-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x0042C16C-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->kernel32.dll-->GetFileAttributesW, Type: IAT modification 0x0042C254-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x0042C130-->00000000 [apphelp.dll]
[1952]BDTUpdateService.exe-->shell32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x738022C4-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->shell32.dll-->kernel32.dll-->MoveFileExW, Type: IAT modification 0x73802240-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->shell32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x73802298-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->user32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77D11524-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D114E0-->00000000 [apphelp.dll]
[1952]BDTUpdateService.exe-->user32.dll-->kernel32.dll-->RegCreateKeyExW, Type: IAT modification 0x77D114B4-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->user32.dll-->kernel32.dll-->RegOpenKeyExW, Type: IAT modification 0x77D11444-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->user32.dll-->kernel32.dll-->RegSetValueExW, Type: IAT modification 0x77D114AC-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->advapi32.dll-->RegCreateKeyExA, Type: IAT modification 0x71201284-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->advapi32.dll-->RegCreateKeyExW, Type: IAT modification 0x712011D0-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->advapi32.dll-->RegDeleteValueA, Type: IAT modification 0x71201244-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->advapi32.dll-->RegDeleteValueW, Type: IAT modification 0x712011D8-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->advapi32.dll-->RegOpenKeyExA, Type: IAT modification 0x7120128C-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->advapi32.dll-->RegOpenKeyExW, Type: IAT modification 0x71201268-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->advapi32.dll-->RegSetValueExA, Type: IAT modification 0x71201288-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->advapi32.dll-->RegSetValueExW, Type: IAT modification 0x712011DC-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->kernel32.dll-->CopyFileA, Type: IAT modification 0x712012DC-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->kernel32.dll-->CreateFileA, Type: IAT modification 0x712014CC-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x712014D0-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->kernel32.dll-->DeleteFileA, Type: IAT modification 0x712014F4-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x71201448-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x7120144C-->00000000 [apphelp.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->kernel32.dll-->MoveFileA, Type: IAT modification 0x71201318-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->kernel32.dll-->MoveFileExA, Type: IAT modification 0x71201444-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->kernel32.dll-->MoveFileExW, Type: IAT modification 0x71201310-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x71201314-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->kernel32.dll-->SetFileAttributesA, Type: IAT modification 0x7120132C-->00000000 [AcGenral.dll]
[1952]BDTUpdateService.exe-->wininet.dll-->kernel32.dll-->SetFileAttributesW, Type: IAT modification 0x71201400-->00000000 [AcGenral.dll]
[2060]OUTLOOK.EXE-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C617B8-->00000000 [apphelp.dll]
[2060]OUTLOOK.EXE-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B611B8-->00000000 [apphelp.dll]
[2060]OUTLOOK.EXE-->kernel32.dll-->SetUnhandledExceptionFilter, Type: Inline - RelativeJump 0x763F3162-->00000000 [MSO.DLL]
[2060]OUTLOOK.EXE-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D114E0-->00000000 [apphelp.dll]
[2060]OUTLOOK.EXE-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x7120144C-->00000000 [apphelp.dll]
[2068]HpqToaster.exe-->user32.dll-->ChangeDisplaySettingsExA, Type: Inline - DirectJump 0x767081B7-->00000000 [unknown_code_page]
[2068]HpqToaster.exe-->user32.dll-->ChangeDisplaySettingsExW, Type: Inline - DirectJump 0x7672FA61-->00000000 [unknown_code_page]
[2068]HpqToaster.exe-->user32.dll-->SetForegroundWindow, Type: Inline - DirectJump 0x766ED3AE-->00000000 [unknown_code_page]
[2068]HpqToaster.exe-->user32.dll-->SetWindowPos, Type: Inline - DirectJump 0x766F3581-->00000000 [unknown_code_page]
[2408]taskhost.exe-->user32.dll-->ChangeDisplaySettingsExA, Type: Inline - DirectJump 0x767081B7-->00000000 [unknown_code_page]
[2408]taskhost.exe-->user32.dll-->ChangeDisplaySettingsExW, Type: Inline - DirectJump 0x7672FA61-->00000000 [unknown_code_page]
[2408]taskhost.exe-->user32.dll-->SetForegroundWindow, Type: Inline - DirectJump 0x766ED3AE-->00000000 [unknown_code_page]
[2408]taskhost.exe-->user32.dll-->SetWindowPos, Type: Inline - DirectJump 0x766F3581-->00000000 [unknown_code_page]
[2500]OUTLOOK.EXE-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C617B8-->00000000 [apphelp.dll]
[2500]OUTLOOK.EXE-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B611B8-->00000000 [apphelp.dll]
[2500]OUTLOOK.EXE-->kernel32.dll-->SetUnhandledExceptionFilter, Type: Inline - RelativeJump 0x763F3162-->00000000 [MSO.DLL]
[2500]OUTLOOK.EXE-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D114E0-->00000000 [apphelp.dll]
[2500]OUTLOOK.EXE-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x7120144C-->00000000 [apphelp.dll]
[3052]HPWAMain.exe-->user32.dll-->ChangeDisplaySettingsExA, Type: Inline - DirectJump 0x767081B7-->00000000 [unknown_code_page]
[3052]HPWAMain.exe-->user32.dll-->ChangeDisplaySettingsExW, Type: Inline - DirectJump 0x7672FA61-->00000000 [unknown_code_page]
[3052]HPWAMain.exe-->user32.dll-->SetForegroundWindow, Type: Inline - DirectJump 0x766ED3AE-->00000000 [unknown_code_page]
[3052]HPWAMain.exe-->user32.dll-->SetWindowPos, Type: Inline - DirectJump 0x766F3581-->00000000 [unknown_code_page]
[3060]QLBCTRL.exe-->user32.dll-->ChangeDisplaySettingsExA, Type: Inline - DirectJump 0x767081B7-->00000000 [unknown_code_page]
[3060]QLBCTRL.exe-->user32.dll-->ChangeDisplaySettingsExW, Type: Inline - DirectJump 0x7672FA61-->00000000 [unknown_code_page]
[3060]QLBCTRL.exe-->user32.dll-->SetForegroundWindow, Type: Inline - DirectJump 0x766ED3AE-->00000000 [unknown_code_page]
[3060]QLBCTRL.exe-->user32.dll-->SetWindowPos, Type: Inline - DirectJump 0x766F3581-->00000000 [unknown_code_page]
[3084]rundll32.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C617B8-->00000000 [apphelp.dll]
[3084]rundll32.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B611B8-->00000000 [apphelp.dll]
[3084]rundll32.exe-->user32.dll-->ChangeDisplaySettingsExA, Type: Inline - DirectJump 0x767081B7-->00000000 [unknown_code_page]
[3084]rundll32.exe-->user32.dll-->ChangeDisplaySettingsExW, Type: Inline - DirectJump 0x7672FA61-->00000000 [unknown_code_page]
[3084]rundll32.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D114E0-->00000000 [apphelp.dll]
[3084]rundll32.exe-->user32.dll-->SetForegroundWindow, Type: Inline - DirectJump 0x766ED3AE-->00000000 [unknown_code_page]
[3084]rundll32.exe-->user32.dll-->SetWindowPos, Type: Inline - DirectJump 0x766F3581-->00000000 [unknown_code_page]
[3084]rundll32.exe-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x7120144C-->00000000 [apphelp.dll]
[3092]realsched.exe-->user32.dll-->ChangeDisplaySettingsExA, Type: Inline - DirectJump 0x767081B7-->00000000 [unknown_code_page]
[3092]realsched.exe-->user32.dll-->ChangeDisplaySettingsExW, Type: Inline - DirectJump 0x7672FA61-->00000000 [unknown_code_page]
[3092]realsched.exe-->user32.dll-->SetForegroundWindow, Type: Inline - DirectJump 0x766ED3AE-->00000000 [unknown_code_page]
[3092]realsched.exe-->user32.dll-->SetWindowPos, Type: Inline - DirectJump 0x766F3581-->00000000 [unknown_code_page]
[3308]OUTLOOK.EXE-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C617B8-->00000000 [apphelp.dll]
[3308]OUTLOOK.EXE-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B611B8-->00000000 [apphelp.dll]
[3308]OUTLOOK.EXE-->kernel32.dll-->SetUnhandledExceptionFilter, Type: Inline - RelativeJump 0x763F3162-->00000000 [MSO.DLL]
[3308]OUTLOOK.EXE-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D114E0-->00000000 [apphelp.dll]
[3308]OUTLOOK.EXE-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x7120144C-->00000000 [apphelp.dll]
[3408]pctsGui.exe-->kernel32.dll-->CreateThread, Type: IAT modification 0x004C0E70-->00000000 [pctsGui.exe]
[3408]pctsGui.exe-->shell32.dll-->kernel32.dll-->QueueUserWorkItem, Type: IAT modification 0x738021C8-->00000000 [pctsGui.exe]
[3408]pctsGui.exe-->user32.dll-->kernel32.dll-->CreateThread, Type: IAT modification 0x77D113B0-->00000000 [pctsGui.exe]
[3408]pctsGui.exe-->wininet.dll-->kernel32.dll-->CreateThread, Type: IAT modification 0x71201360-->00000000 [pctsGui.exe]
[3416]FGuard.exe-->user32.dll-->ChangeDisplaySettingsExA, Type: Inline - DirectJump 0x767081B7-->00000000 [unknown_code_page]
[3416]FGuard.exe-->user32.dll-->ChangeDisplaySettingsExW, Type: Inline - DirectJump 0x7672FA61-->00000000 [unknown_code_page]
[3416]FGuard.exe-->user32.dll-->SetForegroundWindow, Type: Inline - DirectJump 0x766ED3AE-->00000000 [unknown_code_page]
[3416]FGuard.exe-->user32.dll-->SetWindowPos, Type: Inline - DirectJump 0x766F3581-->00000000 [unknown_code_page]
[4068]mswinext.exe-->user32.dll-->ChangeDisplaySettingsExA, Type: Inline - DirectJump 0x767081B7-->00000000 [unknown_code_page]
[4068]mswinext.exe-->user32.dll-->ChangeDisplaySettingsExW, Type: Inline - DirectJump 0x7672FA61-->00000000 [unknown_code_page]
[4068]mswinext.exe-->user32.dll-->SetForegroundWindow, Type: Inline - DirectJump 0x766ED3AE-->00000000 [unknown_code_page]
[4068]mswinext.exe-->user32.dll-->SetWindowPos, Type: Inline - DirectJump 0x766F3581-->00000000 [unknown_code_page]
[4324]GoogleToolbarUser_32.exe-->user32.dll-->ChangeDisplaySettingsExA, Type: Inline - DirectJump 0x767081B7-->00000000 [unknown_code_page]
[4324]GoogleToolbarUser_32.exe-->user32.dll-->ChangeDisplaySettingsExW, Type: Inline - DirectJump 0x7672FA61-->00000000 [unknown_code_page]
[4324]GoogleToolbarUser_32.exe-->user32.dll-->SetForegroundWindow, Type: Inline - DirectJump 0x766ED3AE-->00000000 [unknown_code_page]
[4324]GoogleToolbarUser_32.exe-->user32.dll-->SetWindowPos, Type: Inline - DirectJump 0x766F3581-->00000000 [unknown_code_page]
[440]pctsSvc.exe-->kernel32.dll-->CreateThread, Type: IAT modification 0x004E7FD4-->00000000 [pctsSvc.exe]
[440]pctsSvc.exe-->shell32.dll-->kernel32.dll-->QueueUserWorkItem, Type: IAT modification 0x738021C8-->00000000 [pctsSvc.exe]
[440]pctsSvc.exe-->user32.dll-->kernel32.dll-->CreateThread, Type: IAT modification 0x77D113B0-->00000000 [pctsSvc.exe]
[440]pctsSvc.exe-->wininet.dll-->kernel32.dll-->CreateThread, Type: IAT modification 0x71201360-->00000000 [pctsSvc.exe]
[4672]OUTLOOK.EXE-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C617B8-->00000000 [apphelp.dll]
[4672]OUTLOOK.EXE-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B611B8-->00000000 [apphelp.dll]
[4672]OUTLOOK.EXE-->kernel32.dll-->SetUnhandledExceptionFilter, Type: Inline - RelativeJump 0x763F3162-->00000000 [MSO.DLL]
[4672]OUTLOOK.EXE-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D114E0-->00000000 [apphelp.dll]
[4672]OUTLOOK.EXE-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x7120144C-->00000000 [apphelp.dll]
[5148]iexplore.exe-->user32.dll-->CallNextHookEx, Type: Inline - RelativeJump 0x766ECC8F-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->CreateDialogIndirectParamA, Type: Inline - RelativeJump 0x76709110-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->CreateDialogIndirectParamW, Type: Inline - RelativeJump 0x767108AD-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->CreateDialogParamA, Type: Inline - RelativeJump 0x76703E79-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->CreateDialogParamW, Type: Inline - RelativeJump 0x766E9BFF-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x766F0E51-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x7672D29C-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x76714AA7-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x7672CF6A-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x7671564A-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->EnableWindow, Type: Inline - RelativeJump 0x766EA72E-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->EndDialog, Type: Inline - RelativeJump 0x7671555C-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->GetAsyncKeyState, Type: Inline - RelativeJump 0x766EC09A-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->GetKeyState, Type: Inline - RelativeJump 0x766F4FDA-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->IsDialogMessage, Type: Inline - RelativeJump 0x7670407A-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->IsDialogMessageW, Type: Inline - RelativeJump 0x766F6F06-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->keybd_event, Type: Inline - RelativeJump 0x7673EC9B-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x7673EA29-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x7673EA4D-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x7673E8C9-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x7673E9C3-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->SendInput, Type: Inline - RelativeJump 0x76717055-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->SetCursorPos, Type: Inline - RelativeJump 0x7672C1D8-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->SetKeyboardState, Type: Inline - RelativeJump 0x76716B52-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x766F210A-->00000000 [ieframe.dll]
[5148]iexplore.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x766ECC7B-->00000000 [ieframe.dll]
[5380]svchost.exe-->mswsock.dll+0x00002BBC, Type: Inline - RelativeJump 0x757B2BBC-->00000000 [unknown_code_page]
[5380]svchost.exe-->mswsock.dll+0x000044B1, Type: Inline - RelativeJump 0x757B44B1-->00000000 [unknown_code_page]
[5380]svchost.exe-->mswsock.dll+0x000046B7, Type: Inline - RelativeJump 0x757B46B7-->00000000 [unknown_code_page]
[5380]svchost.exe-->ntdll.dll-->KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x77C66448-->00000000 [unknown_code_page]
[5380]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C65380-->00000000 [unknown_code_page]
[5380]svchost.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x77C65F00-->00000000 [unknown_code_page]
[5608]OUTLOOK.EXE-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C617B8-->00000000 [apphelp.dll]
[5608]OUTLOOK.EXE-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B611B8-->00000000 [apphelp.dll]
[5608]OUTLOOK.EXE-->kernel32.dll-->SetUnhandledExceptionFilter, Type: Inline - RelativeJump 0x763F3162-->00000000 [MSO.DLL]
[5608]OUTLOOK.EXE-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D114E0-->00000000 [apphelp.dll]
[5608]OUTLOOK.EXE-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x7120144C-->00000000 [apphelp.dll]
[5656]explorer.exe-->mswsock.dll+0x00002BBC, Type: Inline - RelativeJump 0x757B2BBC-->00000000 [unknown_code_page]
[5656]explorer.exe-->mswsock.dll+0x000044B1, Type: Inline - RelativeJump 0x757B44B1-->00000000 [unknown_code_page]
[5656]explorer.exe-->mswsock.dll+0x000046B7, Type: Inline - RelativeJump 0x757B46B7-->00000000 [unknown_code_page]
[5656]explorer.exe-->ntdll.dll-->KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x77C66448-->00000000 [unknown_code_page]
[5656]explorer.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C65380-->00000000 [unknown_code_page]
[5656]explorer.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x77C65F00-->00000000 [unknown_code_page]
[5812]iexplore.exe-->advapi32.dll-->kernel32.dll-->CloseHandle, Type: IAT modification 0x77C617C0-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->advapi32.dll-->kernel32.dll-->FreeLibrary, Type: IAT modification 0x77C617C8-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77C617B8-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->advapi32.dll-->kernel32.dll-->ReadFile, Type: IAT modification 0x77C61868-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->advapi32.dll-->kernel32.dll-->WriteFile, Type: IAT modification 0x77C6183C-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->gdi32.dll-->kernel32.dll-->CloseHandle, Type: IAT modification 0x77B611D8-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->gdi32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x77B61154-->00000000 [IEShims.dll]
[5812]iexplore.exe-->gdi32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77B611E0-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->gdi32.dll-->kernel32.dll-->DeleteFileW, Type: IAT modification 0x77B6118C-->00000000 [IEShims.dll]
[5812]iexplore.exe-->gdi32.dll-->kernel32.dll-->FreeLibrary, Type: IAT modification 0x77B611B4-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77B611B8-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x77B61144-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77B61138-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->gdi32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77B611A0-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->gdi32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77B61198-->00000000 [IEShims.dll]
[5812]iexplore.exe-->gdi32.dll-->kernel32.dll-->WriteFile, Type: IAT modification 0x77B611DC-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->mswsock.dll+0x00002BBC, Type: Inline - RelativeJump 0x757B2BBC-->00000000 [unknown_code_page]
[5812]iexplore.exe-->mswsock.dll+0x000044B1, Type: Inline - RelativeJump 0x757B44B1-->00000000 [unknown_code_page]
[5812]iexplore.exe-->mswsock.dll+0x000046B7, Type: Inline - RelativeJump 0x757B46B7-->00000000 [unknown_code_page]
[5812]iexplore.exe-->ntdll.dll-->KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x77C66448-->00000000 [unknown_code_page]
[5812]iexplore.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C65380-->00000000 [unknown_code_page]
[5812]iexplore.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x77C65F00-->00000000 [unknown_code_page]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->CopyFileW, Type: IAT modification 0x738022C4-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->CreateHardLinkW, Type: IAT modification 0x738021D8-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->GetBinaryTypeW, Type: IAT modification 0x738022BC-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileIntW, Type: IAT modification 0x73802254-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionNamesW, Type: IAT modification 0x73802220-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileSectionW, Type: IAT modification 0x738022DC-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x7380224C-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->GetShortPathNameA, Type: IAT modification 0x7380225C-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryA, Type: IAT modification 0x738021BC-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x73802248-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileExW, Type: IAT modification 0x73802240-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->MoveFileW, Type: IAT modification 0x73802298-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->ReplaceFileW, Type: IAT modification 0x73802294-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileSectionW, Type: IAT modification 0x73802218-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x73802214-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->ntdll.dll-->NtQueryDirectoryFile, Type: IAT modification 0x73801B64-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->user32.dll-->CreateDialogParamW, Type: IAT modification 0x73801F54-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->shell32.dll-->user32.dll-->DialogBoxParamW, Type: IAT modification 0x73801E04-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->shell32.dll-->user32.dll-->LoadImageW, Type: IAT modification 0x73801C8C-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->user32.dll-->MessageBoxIndirectW, Type: IAT modification 0x73801F58-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->shell32.dll-->user32.dll-->PrivateExtractIconsW, Type: IAT modification 0x7380202C-->00000000 [IEShims.dll]
[5812]iexplore.exe-->shell32.dll-->user32.dll-->WinHelpW, Type: IAT modification 0x73801E44-->00000000 [IEShims.dll]
[5812]iexplore.exe-->user32.dll-->CallNextHookEx, Type: Inline - RelativeJump 0x766ECC8F-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->CreateDialogIndirectParamA, Type: Inline - RelativeJump 0x76709110-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->CreateDialogIndirectParamW, Type: Inline - RelativeJump 0x767108AD-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->CreateDialogParamA, Type: Inline - RelativeJump 0x76703E79-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->CreateDialogParamW, Type: Inline - RelativeJump 0x766E9BFF-->00000000 [ConduitEngine.dll]
[5812]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x766F0E51-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x7672D29C-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x76714AA7-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x7672CF6A-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x7671564A-->00000000 [ConduitEngine.dll]
[5812]iexplore.exe-->user32.dll-->EnableWindow, Type: Inline - RelativeJump 0x766EA72E-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->EndDialog, Type: Inline - RelativeJump 0x7671555C-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->GetAsyncKeyState, Type: Inline - RelativeJump 0x766EC09A-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->GetKeyState, Type: Inline - RelativeJump 0x766F4FDA-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->IsDialogMessage, Type: Inline - RelativeJump 0x7670407A-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->IsDialogMessageW, Type: Inline - RelativeJump 0x766F6F06-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->CloseHandle, Type: IAT modification 0x77D113D4-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->CreateFileW, Type: IAT modification 0x77D11524-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->CreateProcessW, Type: IAT modification 0x77D113E4-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->FindClose, Type: IAT modification 0x77D11414-->00000000 [IEShims.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->FindFirstFileW, Type: IAT modification 0x77D1141C-->00000000 [IEShims.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->FindNextFileW, Type: IAT modification 0x77D11418-->00000000 [IEShims.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->FreeLibrary, Type: IAT modification 0x77D114DC-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->GetPrivateProfileStringW, Type: IAT modification 0x77D114A8-->00000000 [IEShims.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77D114E0-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryExA, Type: IAT modification 0x77D11490-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryExW, Type: IAT modification 0x77D11398-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->LoadLibraryW, Type: IAT modification 0x77D114E4-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->ReadFile, Type: IAT modification 0x77D113D8-->00000000 [PCTBDCore.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->SearchPathW, Type: IAT modification 0x77D11390-->00000000 [IEShims.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->SetCurrentDirectoryW, Type: IAT modification 0x77D11408-->00000000 [IEShims.dll]
[5812]iexplore.exe-->user32.dll-->kernel32.dll-->WritePrivateProfileStringW, Type: IAT modification 0x77D1152C-->00000000 [IEShims.dll]
[5812]iexplore.exe-->user32.dll-->keybd_event, Type: Inline - RelativeJump 0x7673EC9B-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x7673EA29-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x7673EA4D-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x7673E8C9-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x7673E9C3-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->SendInput, Type: Inline - RelativeJump 0x76717055-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->SetCursorPos, Type: Inline - RelativeJump 0x7672C1D8-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->SetKeyboardState, Type: Inline - RelativeJump 0x76716B52-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->SetWindowsHookExW, Type: Inline - RelativeJump 0x766F210A-->00000000 [ieframe.dll]
[5812]iexplore.exe-->user32.dll-->TrackPopupMenu, Type: Inline - RelativeJump 0x76714B3B-->00000000 [ConduitEngine.dll]
[5812]iexplore.exe-->user32.dll-->TrackPopupMenuEx, Type: Inline - RelativeJump 0x76715F72-->00000000 [ConduitEngine.dll]
[5812]iexplore.exe-->user32.dll-->UnhookWindowsHookEx, Type: Inline - RelativeJump 0x766ECC7B-->00000000 [ieframe.dll]
[5916]iexplore.exe-->mswsock.dll+0x00002BBC, Type: Inline - RelativeJump 0x757B2BBC-->00000000 [unknown_code_page]
[5916]iexplore.exe-->mswsock.dll+0x000044B1, Type: Inline - RelativeJump 0x757B44B1-->00000000 [unknown_code_page]
[5916]iexplore.exe-->mswsock.dll+0x000046B7, Type: Inline - RelativeJump 0x757B46B7-->00000000 [unknown_code_page]
[5916]iexplore.exe-->ntdll.dll-->KiUserExceptionDispatcher, Type: Inline - RelativeJump 0x77C66448-->00000000 [unknown_code_page]
[5916]iexplore.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x77C65380-->00000000 [unknown_code_page]
[5916]iexplore.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x77C65F00-->00000000 [unknown_code_page]
[5916]iexplore.exe-->user32.dll-->CreateDialogParamW, Type: Inline - RelativeJump 0x766E9BFF-->00000000 [tbSwa0.dll]
[5916]iexplore.exe-->user32.dll-->CreateWindowExW, Type: Inline - RelativeJump 0x766F0E51-->00000000 [ieframe.dll]
[5916]iexplore.exe-->user32.dll-->DialogBoxIndirectParamA, Type: Inline - RelativeJump 0x7672D29C-->00000000 [ieframe.dll]
[5916]iexplore.exe-->user32.dll-->DialogBoxIndirectParamW, Type: Inline - RelativeJump 0x76714AA7-->00000000 [ieframe.dll]
[5916]iexplore.exe-->user32.dll-->DialogBoxParamA, Type: Inline - RelativeJump 0x7672CF6A-->00000000 [ieframe.dll]
[5916]iexplore.exe-->user32.dll-->DialogBoxParamW, Type: Inline - RelativeJump 0x7671564A-->00000000 [tbSwa0.dll]
[5916]iexplore.exe-->user32.dll-->MessageBoxExA, Type: Inline - RelativeJump 0x7673EA29-->00000000 [ieframe.dll]
[5916]iexplore.exe-->user32.dll-->MessageBoxExW, Type: Inline - RelativeJump 0x7673EA4D-->00000000 [ieframe.dll]
[5916]iexplore.exe-->user32.dll-->MessageBoxIndirectA, Type: Inline - RelativeJump 0x7673E8C9-->00000000 [ieframe.dll]
[5916]iexplore.exe-->user32.dll-->MessageBoxIndirectW, Type: Inline - RelativeJump 0x7673E9C3-->00000000 [ieframe.dll]
[5916]iexplore.exe-->user32.dll-->TrackPopupMenu, Type: Inline - RelativeJump 0x76714B3B-->00000000 [tbSwa0.dll]
[5916]iexplore.exe-->user32.dll-->TrackPopupMenuEx, Type: Inline - RelativeJump 0x76715F72-->00000000 [tbSwa0.dll]
[6128]SCServer.exe-->user32.dll-->ChangeDisplaySettingsExA, Type: Inline - DirectJump 0x767081B7-->00000000 [unknown_code_page]
[6128]SCServer.exe-->user32.dll-->ChangeDisplaySettingsExW, Type: Inline - DirectJump 0x7672FA61-->00000000 [unknown_code_page]
[6128]SCServer.exe-->user32.dll-->SetForegroundWindow, Type: Inline - DirectJump 0x766ED3AE-->00000000 [unknown_code_page]
[6128]SCServer.exe-->user32.dll-->SetWindowPos, Type: Inline - DirectJump 0x766F3581-->00000000 [unknown_code_page]
!!POSSIBLE ROOTKIT ACTIVITY DETECTED!! =)