Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- GMER 2.1.19163 - http://www.gmer.net
- Rootkit scan 2013-04-30 20:25:14
- Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.JE4O 698,64GB
- Running: 65bv0szz.exe; Driver: C:\Users\Lida\AppData\Local\Temp\kwlyyuod.sys
- ---- User code sections - GMER 2.1 ----
- .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1800] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000774cefe0 5 bytes JMP 000000016fff0148
- .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1800] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000774f99b0 7 bytes JMP 000000016fff00d8
- .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1800] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000775094d0 5 bytes JMP 000000016fff0180
- .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1800] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077509640 5 bytes JMP 000000016fff0110
- .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1800] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007752a500 7 bytes JMP 000000016fff01b8
- .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1800] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1800] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1800] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1800] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1800] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1800] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1800] C:\Windows\system32\ole32.dll!CoCreateInstance 000007feff757490 11 bytes JMP 000007fffe2c0228
- .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1800] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007feff76bf00 7 bytes JMP 000007fffe2c0260
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1648] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076d81465 2 bytes [D8, 76]
- .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2132] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076d814bb 2 bytes [D8, 76]
- .text ... * 2
- .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[2280] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076d81465 2 bytes [D8, 76]
- .text C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe[2280] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076d814bb 2 bytes [D8, 76]
- .text ... * 2
- .text C:\Windows\system32\Dwm.exe[2512] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Windows\system32\Dwm.exe[2512] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Windows\system32\Dwm.exe[2512] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Windows\system32\Dwm.exe[2512] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Windows\system32\Dwm.exe[2512] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Windows\system32\Dwm.exe[2512] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Windows\system32\Dwm.exe[2512] C:\Windows\system32\dxgi.dll!CreateDXGIFactory 000007fef7cbdc88 5 bytes JMP 000007fff7c900d8
- .text C:\Windows\system32\Dwm.exe[2512] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1 000007fef7cbde10 5 bytes JMP 000007fff7c90110
- .text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[3900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076d81465 2 bytes [D8, 76]
- .text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[3900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076d814bb 2 bytes [D8, 76]
- .text ... * 2
- .text C:\Windows\System32\igfxpers.exe[3912] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000774cefe0 5 bytes JMP 000000016fff0148
- .text C:\Windows\System32\igfxpers.exe[3912] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000774f99b0 7 bytes JMP 000000016fff00d8
- .text C:\Windows\System32\igfxpers.exe[3912] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000775094d0 5 bytes JMP 000000016fff0180
- .text C:\Windows\System32\igfxpers.exe[3912] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077509640 5 bytes JMP 000000016fff0110
- .text C:\Windows\System32\igfxpers.exe[3912] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007752a500 7 bytes JMP 000000016fff01b8
- .text C:\Windows\System32\igfxpers.exe[3912] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Windows\System32\igfxpers.exe[3912] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Windows\System32\igfxpers.exe[3912] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Windows\System32\igfxpers.exe[3912] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Windows\System32\igfxpers.exe[3912] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Windows\System32\igfxpers.exe[3912] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Windows\System32\igfxpers.exe[3912] C:\Windows\system32\ole32.dll!CoCreateInstance 000007feff757490 11 bytes JMP 000007fffe2c0228
- .text C:\Windows\System32\igfxpers.exe[3912] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007feff76bf00 7 bytes JMP 000007fffe2c0260
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3140] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000774cefe0 5 bytes JMP 000000016fff0148
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3140] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000774f99b0 7 bytes JMP 000000016fff00d8
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3140] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000775094d0 5 bytes JMP 000000016fff0180
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3140] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077509640 5 bytes JMP 000000016fff0110
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3140] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007752a500 7 bytes JMP 000000016fff01b8
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3140] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3140] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3140] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3140] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3140] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3140] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3140] C:\Windows\system32\ole32.dll!CoCreateInstance 000007feff757490 11 bytes JMP 000007fffe2c0228
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3140] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007feff76bf00 7 bytes JMP 000007fffe2c0260
- .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3120] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000774cefe0 5 bytes JMP 000000016fff0148
- .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3120] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000774f99b0 7 bytes JMP 000000016fff00d8
- .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3120] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000775094d0 5 bytes JMP 000000016fff0180
- .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3120] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077509640 5 bytes JMP 000000016fff0110
- .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3120] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007752a500 7 bytes JMP 000000016fff01b8
- .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3120] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3120] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3120] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3120] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3120] C:\Windows\system32\ole32.dll!CoCreateInstance 000007feff757490 11 bytes JMP 000007fffe2c0228
- .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3120] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007feff76bf00 7 bytes JMP 000007fffe2c0260
- .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3120] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3120] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Program Files\Apoint2K\Apoint.exe[3156] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000774cefe0 5 bytes JMP 000000016fff0148
- .text C:\Program Files\Apoint2K\Apoint.exe[3156] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000774f99b0 7 bytes JMP 000000016fff00d8
- .text C:\Program Files\Apoint2K\Apoint.exe[3156] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000775094d0 5 bytes JMP 000000016fff0180
- .text C:\Program Files\Apoint2K\Apoint.exe[3156] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077509640 5 bytes JMP 000000016fff0110
- .text C:\Program Files\Apoint2K\Apoint.exe[3156] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007752a500 7 bytes JMP 000000016fff01b8
- .text C:\Program Files\Apoint2K\Apoint.exe[3156] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Program Files\Apoint2K\Apoint.exe[3156] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Program Files\Apoint2K\Apoint.exe[3156] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Program Files\Apoint2K\Apoint.exe[3156] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Program Files\Apoint2K\Apoint.exe[3156] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Program Files\Apoint2K\Apoint.exe[3156] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Program Files\Apoint2K\Apoint.exe[3156] C:\Windows\system32\ole32.dll!CoCreateInstance 000007feff757490 11 bytes JMP 000007fffe2c0228
- .text C:\Program Files\Apoint2K\Apoint.exe[3156] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007feff76bf00 7 bytes JMP 000007fffe2c0260
- .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[3204] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000774cefe0 5 bytes JMP 000000016fff0148
- .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[3204] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000774f99b0 7 bytes JMP 000000016fff00d8
- .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[3204] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000775094d0 5 bytes JMP 000000016fff0180
- .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[3204] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077509640 5 bytes JMP 000000016fff0110
- .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[3204] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007752a500 7 bytes JMP 000000016fff01b8
- .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[3204] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[3204] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[3204] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[3204] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[3204] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[3204] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[3204] C:\Windows\system32\ole32.dll!CoCreateInstance 000007feff757490 11 bytes JMP 000007fffe2c0228
- .text C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[3204] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007feff76bf00 7 bytes JMP 000007fffe2c0260
- .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3208] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000774cefe0 5 bytes JMP 000000016fff0148
- .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3208] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000774f99b0 7 bytes JMP 000000016fff00d8
- .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3208] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000775094d0 5 bytes JMP 000000016fff0180
- .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3208] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077509640 5 bytes JMP 000000016fff0110
- .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3208] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007752a500 7 bytes JMP 000000016fff01b8
- .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3208] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3208] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3208] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3208] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3208] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3208] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3208] C:\Windows\system32\ole32.dll!CoCreateInstance 000007feff757490 11 bytes JMP 000007fffe2c0228
- .text C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe[3208] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007feff76bf00 7 bytes JMP 000007fffe2c0260
- .text C:\Dolby PCEE4\pcee4.exe[4520] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 00000000774cefe0 5 bytes JMP 000000016fff0148
- .text C:\Dolby PCEE4\pcee4.exe[4520] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 00000000774f99b0 7 bytes JMP 000000016fff00d8
- .text C:\Dolby PCEE4\pcee4.exe[4520] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 00000000775094d0 5 bytes JMP 000000016fff0180
- .text C:\Dolby PCEE4\pcee4.exe[4520] C:\Windows\system32\KERNEL32.dll!K32GetModuleFileNameExW 0000000077509640 5 bytes JMP 000000016fff0110
- .text C:\Dolby PCEE4\pcee4.exe[4520] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 000000007752a500 7 bytes JMP 000000016fff01b8
- .text C:\Dolby PCEE4\pcee4.exe[4520] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Dolby PCEE4\pcee4.exe[4520] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Dolby PCEE4\pcee4.exe[4520] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Dolby PCEE4\pcee4.exe[4520] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Dolby PCEE4\pcee4.exe[4520] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Dolby PCEE4\pcee4.exe[4520] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Dolby PCEE4\pcee4.exe[4520] C:\Windows\system32\ole32.dll!CoCreateInstance 000007feff757490 11 bytes JMP 000007fffe2c0228
- .text C:\Dolby PCEE4\pcee4.exe[4520] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007feff76bf00 7 bytes JMP 000007fffe2c0260
- .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4644] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000774cefe0 5 bytes JMP 000000016fff0148
- .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4644] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000774f99b0 7 bytes JMP 000000016fff00d8
- .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4644] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000775094d0 5 bytes JMP 000000016fff0180
- .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4644] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077509640 5 bytes JMP 000000016fff0110
- .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4644] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007752a500 7 bytes JMP 000000016fff01b8
- .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4644] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4644] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4644] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4644] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4644] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4644] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076d81465 2 bytes [D8, 76]
- .text C:\Program Files (x86)\Launch Manager\LManager.exe[4736] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076d814bb 2 bytes [D8, 76]
- .text ... * 2
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4808] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[4844] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[4844] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[4844] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[4844] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[4844] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[4844] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe[2540] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe[2540] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe[2540] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe[2540] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Kaspersky Lab\Kaspersky PURE 2.0\avp.exe[2540] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4960] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files\Apoint2K\ApMsgFwd.exe[4036] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000774cefe0 5 bytes JMP 000000016fff0148
- .text C:\Program Files\Apoint2K\ApMsgFwd.exe[4036] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000774f99b0 7 bytes JMP 000000016fff00d8
- .text C:\Program Files\Apoint2K\ApMsgFwd.exe[4036] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000775094d0 5 bytes JMP 000000016fff0180
- .text C:\Program Files\Apoint2K\ApMsgFwd.exe[4036] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077509640 5 bytes JMP 000000016fff0110
- .text C:\Program Files\Apoint2K\ApMsgFwd.exe[4036] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007752a500 7 bytes JMP 000000016fff01b8
- .text C:\Program Files\Apoint2K\ApMsgFwd.exe[4036] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Program Files\Apoint2K\ApMsgFwd.exe[4036] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Program Files\Apoint2K\ApMsgFwd.exe[4036] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Program Files\Apoint2K\ApMsgFwd.exe[4036] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Program Files\Apoint2K\ApMsgFwd.exe[4036] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Program Files\Apoint2K\ApMsgFwd.exe[4036] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Program Files\Apoint2K\HidFind.exe[3316] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Program Files\Apoint2K\HidFind.exe[3316] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Program Files\Apoint2K\HidFind.exe[3316] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Program Files\Apoint2K\HidFind.exe[3316] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Program Files\Apoint2K\HidFind.exe[3316] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Program Files\Apoint2K\HidFind.exe[3316] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Program Files\Apoint2K\Apntex.exe[3016] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000774cefe0 5 bytes JMP 000000016fff0148
- .text C:\Program Files\Apoint2K\Apntex.exe[3016] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000774f99b0 7 bytes JMP 000000016fff00d8
- .text C:\Program Files\Apoint2K\Apntex.exe[3016] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000775094d0 5 bytes JMP 000000016fff0180
- .text C:\Program Files\Apoint2K\Apntex.exe[3016] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077509640 5 bytes JMP 000000016fff0110
- .text C:\Program Files\Apoint2K\Apntex.exe[3016] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007752a500 7 bytes JMP 000000016fff01b8
- .text C:\Program Files\Apoint2K\Apntex.exe[3016] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Program Files\Apoint2K\Apntex.exe[3016] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Program Files\Apoint2K\Apntex.exe[3016] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Program Files\Apoint2K\Apntex.exe[3016] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Program Files\Apoint2K\Apntex.exe[3016] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Program Files\Apoint2K\Apntex.exe[3016] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\Launch Manager\LMworker.exe[3652] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[3212] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[2508] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Windows\system32\wbem\unsecapp.exe[3932] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Windows\system32\wbem\unsecapp.exe[3932] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Windows\system32\wbem\unsecapp.exe[3932] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Windows\system32\wbem\unsecapp.exe[3932] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Windows\system32\wbem\unsecapp.exe[3932] C:\Windows\system32\ole32.dll!CoCreateInstance 000007feff757490 11 bytes JMP 000007fffe2c0228
- .text C:\Windows\system32\wbem\unsecapp.exe[3932] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007feff76bf00 7 bytes JMP 000007fffe2c0260
- .text C:\Windows\system32\wbem\unsecapp.exe[3932] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Windows\system32\wbem\unsecapp.exe[3932] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076d81465 2 bytes [D8, 76]
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5448] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076d814bb 2 bytes [D8, 76]
- .text ... * 2
- ? C:\Windows\system32\mssprxy.dll [5448] entry point in ".rdata" section 000000006afb71e6
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 0000000077d6f991 7 bytes {MOV EDX, 0x1fb228; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 0000000077d6fbd5 7 bytes {MOV EDX, 0x1fb268; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 0000000077d6fc05 7 bytes {MOV EDX, 0x1fb1a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 0000000077d6fc1d 7 bytes {MOV EDX, 0x1fb128; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 0000000077d6fc35 7 bytes {MOV EDX, 0x1fb328; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 0000000077d6fc65 7 bytes {MOV EDX, 0x1fb368; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 0000000077d6fce5 7 bytes {MOV EDX, 0x1fb2e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 0000000077d6fcfd 7 bytes {MOV EDX, 0x1fb2a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 0000000077d6fd49 7 bytes {MOV EDX, 0x1fb068; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 0000000077d6fe41 7 bytes {MOV EDX, 0x1fb0a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077d70099 7 bytes {MOV EDX, 0x1fb028; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 0000000077d710a5 7 bytes {MOV EDX, 0x1fb1e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 0000000077d7111d 7 bytes {MOV EDX, 0x1fb168; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077d71321 7 bytes {MOV EDX, 0x1fb0e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076d81465 2 bytes [D8, 76]
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076d814bb 2 bytes [D8, 76]
- .text ... * 2
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 0000000077d6f991 7 bytes {MOV EDX, 0xa78228; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 0000000077d6fbd5 7 bytes {MOV EDX, 0xa78268; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 0000000077d6fc05 7 bytes {MOV EDX, 0xa781a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 0000000077d6fc1d 7 bytes {MOV EDX, 0xa78128; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 0000000077d6fc35 7 bytes {MOV EDX, 0xa78328; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 0000000077d6fc65 7 bytes {MOV EDX, 0xa78368; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 0000000077d6fce5 7 bytes {MOV EDX, 0xa782e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 0000000077d6fcfd 7 bytes {MOV EDX, 0xa782a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 0000000077d6fd49 7 bytes {MOV EDX, 0xa78068; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 0000000077d6fe41 7 bytes {MOV EDX, 0xa780a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077d70099 7 bytes {MOV EDX, 0xa78028; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 0000000077d710a5 7 bytes {MOV EDX, 0xa781e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 0000000077d7111d 7 bytes {MOV EDX, 0xa78168; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077d71321 7 bytes {MOV EDX, 0xa780e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076d81465 2 bytes [D8, 76]
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5668] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076d814bb 2 bytes [D8, 76]
- .text ... * 2
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 0000000077d6f991 7 bytes {MOV EDX, 0x46a628; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 0000000077d6fbd5 7 bytes {MOV EDX, 0x46a668; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 0000000077d6fc05 7 bytes {MOV EDX, 0x46a5a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 0000000077d6fc1d 7 bytes {MOV EDX, 0x46a528; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 0000000077d6fc35 7 bytes {MOV EDX, 0x46a728; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 0000000077d6fc65 7 bytes {MOV EDX, 0x46a768; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 0000000077d6fce5 7 bytes {MOV EDX, 0x46a6e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 0000000077d6fcfd 7 bytes {MOV EDX, 0x46a6a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 0000000077d6fd49 7 bytes {MOV EDX, 0x46a468; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 0000000077d6fe41 7 bytes {MOV EDX, 0x46a4a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077d70099 7 bytes {MOV EDX, 0x46a428; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 0000000077d710a5 7 bytes {MOV EDX, 0x46a5e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 0000000077d7111d 7 bytes {MOV EDX, 0x46a568; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077d71321 7 bytes {MOV EDX, 0x46a4e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076d81465 2 bytes [D8, 76]
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5736] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076d814bb 2 bytes [D8, 76]
- .text ... * 2
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 0000000077d6f991 7 bytes {MOV EDX, 0x2cae28; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 0000000077d6fbd5 7 bytes {MOV EDX, 0x2cae68; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 0000000077d6fc05 7 bytes {MOV EDX, 0x2cada8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 0000000077d6fc1d 7 bytes {MOV EDX, 0x2cad28; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 0000000077d6fc35 7 bytes {MOV EDX, 0x2caf28; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 0000000077d6fc65 7 bytes {MOV EDX, 0x2caf68; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 0000000077d6fce5 7 bytes {MOV EDX, 0x2caee8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 0000000077d6fcfd 7 bytes {MOV EDX, 0x2caea8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 0000000077d6fd49 7 bytes {MOV EDX, 0x2cac68; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 0000000077d6fe41 7 bytes {MOV EDX, 0x2caca8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077d70099 7 bytes {MOV EDX, 0x2cac28; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 0000000077d710a5 7 bytes {MOV EDX, 0x2cade8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 0000000077d7111d 7 bytes {MOV EDX, 0x2cad68; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077d71321 7 bytes {MOV EDX, 0x2cace8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076d81465 2 bytes [D8, 76]
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5836] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076d814bb 2 bytes [D8, 76]
- .text ... * 2
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 0000000077d6f991 7 bytes {MOV EDX, 0xdb2228; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 0000000077d6fbd5 7 bytes {MOV EDX, 0xdb2268; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 0000000077d6fc05 7 bytes {MOV EDX, 0xdb21a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 0000000077d6fc1d 7 bytes {MOV EDX, 0xdb2128; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 0000000077d6fc35 7 bytes {MOV EDX, 0xdb2328; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 0000000077d6fc65 7 bytes {MOV EDX, 0xdb2368; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 0000000077d6fce5 7 bytes {MOV EDX, 0xdb22e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 0000000077d6fcfd 7 bytes {MOV EDX, 0xdb22a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 0000000077d6fd49 7 bytes {MOV EDX, 0xdb2068; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 0000000077d6fe41 7 bytes {MOV EDX, 0xdb20a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077d70099 7 bytes {MOV EDX, 0xdb2028; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 0000000077d710a5 7 bytes {MOV EDX, 0xdb21e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 0000000077d7111d 7 bytes {MOV EDX, 0xdb2168; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077d71321 7 bytes {MOV EDX, 0xdb20e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076d81465 2 bytes [D8, 76]
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2600] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076d814bb 2 bytes [D8, 76]
- .text ... * 2
- .text C:\Windows\system32\taskeng.exe[3516] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefe2d3460 7 bytes JMP 000007fffe2c00d8
- .text C:\Windows\system32\taskeng.exe[3516] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefe2d9940 6 bytes JMP 000007fffe2c0148
- .text C:\Windows\system32\taskeng.exe[3516] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefe2d9fb0 5 bytes JMP 000007fffe2c0180
- .text C:\Windows\system32\taskeng.exe[3516] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefe2da150 5 bytes JMP 000007fffe2c0110
- .text C:\Windows\system32\taskeng.exe[3516] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007feff9e89e0 8 bytes JMP 000007fffe2c01f0
- .text C:\Windows\system32\taskeng.exe[3516] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007feff9ebe40 8 bytes JMP 000007fffe2c01b8
- .text C:\Windows\system32\taskeng.exe[3516] C:\Windows\system32\ole32.dll!CoCreateInstance 000007feff757490 11 bytes JMP 000007fffe2c0228
- .text C:\Windows\system32\taskeng.exe[3516] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007feff76bf00 7 bytes JMP 000007fffe2c0260
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 0000000077d6f991 7 bytes {MOV EDX, 0x272e28; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 0000000077d6fbd5 7 bytes {MOV EDX, 0x272e68; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 0000000077d6fc05 7 bytes {MOV EDX, 0x272da8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 0000000077d6fc1d 7 bytes {MOV EDX, 0x272d28; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 0000000077d6fc35 7 bytes {MOV EDX, 0x272f28; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 0000000077d6fc65 7 bytes {MOV EDX, 0x272f68; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 0000000077d6fce5 7 bytes {MOV EDX, 0x272ee8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 0000000077d6fcfd 7 bytes {MOV EDX, 0x272ea8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 0000000077d6fd49 7 bytes {MOV EDX, 0x272c68; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 0000000077d6fe41 7 bytes {MOV EDX, 0x272ca8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077d70099 7 bytes {MOV EDX, 0x272c28; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 0000000077d710a5 7 bytes {MOV EDX, 0x272de8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 0000000077d7111d 7 bytes {MOV EDX, 0x272d68; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077d71321 7 bytes {MOV EDX, 0x272ce8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076d81465 2 bytes [D8, 76]
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1736] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076d814bb 2 bytes [D8, 76]
- .text ... * 2
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[2752] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 0000000077d6f991 7 bytes {MOV EDX, 0x8e3628; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 0000000077d6fbd5 7 bytes {MOV EDX, 0x8e3668; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 0000000077d6fc05 7 bytes {MOV EDX, 0x8e35a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 0000000077d6fc1d 7 bytes {MOV EDX, 0x8e3528; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 0000000077d6fc35 7 bytes {MOV EDX, 0x8e3728; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 0000000077d6fc65 7 bytes {MOV EDX, 0x8e3768; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 0000000077d6fce5 7 bytes {MOV EDX, 0x8e36e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 0000000077d6fcfd 7 bytes {MOV EDX, 0x8e36a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 0000000077d6fd49 7 bytes {MOV EDX, 0x8e3468; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 0000000077d6fe41 7 bytes {MOV EDX, 0x8e34a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077d70099 7 bytes {MOV EDX, 0x8e3428; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 0000000077d710a5 7 bytes {MOV EDX, 0x8e35e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 0000000077d7111d 7 bytes {MOV EDX, 0x8e3568; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077d71321 7 bytes {MOV EDX, 0x8e34e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076d81465 2 bytes [D8, 76]
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[2760] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076d814bb 2 bytes [D8, 76]
- .text ... * 2
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 0000000077d6f991 7 bytes {MOV EDX, 0x415a28; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 0000000077d6fbd5 7 bytes {MOV EDX, 0x415a68; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 0000000077d6fc05 7 bytes {MOV EDX, 0x4159a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 0000000077d6fc1d 7 bytes {MOV EDX, 0x415928; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 0000000077d6fc35 7 bytes {MOV EDX, 0x415b28; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 0000000077d6fc65 7 bytes {MOV EDX, 0x415b68; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 0000000077d6fce5 7 bytes {MOV EDX, 0x415ae8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 0000000077d6fcfd 7 bytes {MOV EDX, 0x415aa8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 0000000077d6fd49 7 bytes {MOV EDX, 0x415868; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 0000000077d6fe41 7 bytes {MOV EDX, 0x4158a8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077d70099 7 bytes {MOV EDX, 0x415828; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 0000000077d710a5 7 bytes {MOV EDX, 0x4159e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 0000000077d7111d 7 bytes {MOV EDX, 0x415968; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077d71321 7 bytes {MOV EDX, 0x4158e8; JMP RDX}
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076d81465 2 bytes [D8, 76]
- .text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3716] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076d814bb 2 bytes [D8, 76]
- .text ... * 2
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 0000000077231429 7 bytes JMP 00000001727712ad
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007724b223 5 bytes JMP 00000001727715be
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000772c88f4 7 bytes JMP 0000000172771357
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 00000000772c8979 5 bytes JMP 00000001727716e0
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 00000000772c8ccf 5 bytes JMP 0000000172771028
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770d1d1b 5 bytes JMP 00000001727711ef
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770d1dc9 5 bytes JMP 0000000172771023
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770d2aa4 5 bytes JMP 000000017277156e
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770d2d0a 5 bytes JMP 0000000172771294
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007564e9a2 5 bytes JMP 00000001727715d7
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007564ebdc 5 bytes JMP 00000001727711b8
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075da8a29 5 bytes JMP 0000000172771050
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075db4572 5 bytes JMP 00000001727710d2
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075a85ea5 5 bytes JMP 0000000172771609
- .text C:\Users\Lida\Desktop\65bv0szz.exe[4592] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075ab9d0b 5 bytes JMP 0000000172771249
- ---- Registry - GMER 2.1 ----
- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\74e543004635
- Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\74e543004635 (not active ControlSet)
- ---- EOF - GMER 2.1 ----
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement