flyingnoodls | 15.05.2013 12:05 | Gmer log Teil 1 Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-05-15 12:41:48
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.AX00 298,09GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Joe\AppData\Local\Temp\fxldrpoc.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560 fffff800037fc000 65 bytes [00, 00, 15, 02, 46, 69, 6C, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 626 fffff800037fc042 4 bytes [00, 00, 00, 00]
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe[2284] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000752e1465 2 bytes [2E, 75]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe[2284] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000752e14bb 2 bytes [2E, 75]
.text ... * 2
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000778208fc 6 bytes [68, A0, CF, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000778325fd 6 bytes [68, BD, 57, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007783c45a 6 bytes [68, CB, D0, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077842a63 6 bytes [68, 03, 58, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077864128 6 bytes [68, 49, 58, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007786e659 6 bytes [68, 8F, 58, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007605455c 6 bytes [68, 34, D3, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000760579f8 6 bytes [68, F3, D2, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075d23918 6 bytes [68, 27, E3, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075d24296 6 bytes [68, 38, DF, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075d24406 6 bytes [68, 80, E3, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WS2_32.dll!send 0000000075d26f01 6 bytes [68, 5F, E3, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075d37673 6 bytes [68, C8, DE, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000075b1c664 6 bytes [68, DC, 08, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000075b1e13a 6 bytes [68, 7C, 0A, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000075b1f8d8 6 bytes [68, 49, 09, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000075b23184 6 bytes [68, 50, 0A, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000075b45761 6 bytes [68, 1E, 06, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000075b45fef 6 bytes [68, DA, 05, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000075b4632d 6 bytes [68, 62, 06, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000075b4fa49 6 bytes [68, 77, 09, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000075b5f564 6 bytes [68, 0C, 07, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000075b5f639 6 bytes [68, 46, 08, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000075b74f2f 6 bytes [68, F6, 09, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000075b7525a 6 bytes [68, B7, 06, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000075bbece5 6 bytes [68, A9, 07, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000075bbedb7 6 bytes [68, 91, 08, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!GetDC 00000000751f72c4 6 bytes [68, 92, 18, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000751f7446 6 bytes [68, 10, 19, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000751f7809 6 bytes [68, A5, 5D, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000751f78e2 6 bytes [68, 22, DE, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000751f7bd3 6 bytes [68, 4A, DE, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000751f8048 6 bytes [68, D1, 18, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000751f8a65 6 bytes [68, C1, 5A, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000751fb17d 6 bytes [68, 5B, 5B, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000751fdb98 6 bytes [68, AD, 5B, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000752005ba 6 bytes [68, 72, DE, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000075200d32 6 bytes [68, F3, 59, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000075201218 6 bytes [68, 55, DC, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!EndPaint 0000000075201341 6 bytes [68, F7, 17, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000075201361 6 bytes [68, 87, 17, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000075202a8d 6 bytes [68, 23, DC, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!GetCapture 0000000075202aac 6 bytes [68, 83, DD, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000075203391 6 bytes [68, 37, 18, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!RegisterClassA 000000007520434b 6 bytes [68, 0E, 5B, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075205f74 6 bytes [68, 9D, DE, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000075206222 6 bytes [68, E3, 19, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!CallWindowProcA 000000007520792f 6 bytes [68, 3C, 5A, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000075207fbb 6 bytes [68, 1E, 59, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 000000007520810c 6 bytes [68, AD, 59, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000752085c1 6 bytes [68, D5, 58, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000752086b4 6 bytes [68, 67, 59, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007521d41f 6 bytes [68, 50, 19, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!ReleaseCapture 000000007521ed49 6 bytes [68, 33, DD, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!SetCapture 000000007521ed56 6 bytes [68, D9, DC, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000075239854 6 bytes [68, 9F, 57, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075239cfd 6 bytes [68, 9C, DC, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075239f1d 6 bytes [68, 54, 5F, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000752587cb 6 bytes [68, 4F, 57, 9A, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007570c592 6 bytes [68, B1, D3, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000075742538 6 bytes [68, 9A, D3, 99, 02, C3]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000752e1465 2 bytes [2E, 75]
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000752e14bb 2 bytes [2E, 75]
.text ... * 2
.text C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe[2936] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000075841224 6 bytes [68, 89, 7E, 99, 02, C3]
.text C:\Users\Joe\AppData\Roaming\Elaw\cyim.exe[2988] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075d24296 6 bytes [68, 38, DF, 41, 00, C3]
.text C:\Users\Joe\AppData\Roaming\Elaw\cyim.exe[2988] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075d37673 6 bytes [68, C8, DE, 41, 00, C3]
.text C:\Users\Joe\AppData\Roaming\Elaw\cyim.exe[2988] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000752e1465 2 bytes [2E, 75]
.text C:\Users\Joe\AppData\Roaming\Elaw\cyim.exe[2988] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000752e14bb 2 bytes [2E, 75]
.text ... * 2
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000778208fc 6 bytes [68, A0, CF, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000778325fd 6 bytes [68, BD, 57, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007783c45a 6 bytes [68, CB, D0, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077842a63 6 bytes [68, 03, 58, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077864128 6 bytes [68, 49, 58, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007786e659 6 bytes [68, 8F, 58, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007605455c 6 bytes [68, 34, D3, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000760579f8 6 bytes [68, F3, D2, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!GetDC 00000000751f72c4 6 bytes [68, 92, 18, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000751f7446 6 bytes [68, 10, 19, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000751f7809 6 bytes [68, A5, 5D, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000751f78e2 6 bytes [68, 22, DE, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000751f7bd3 6 bytes [68, 4A, DE, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000751f8048 6 bytes [68, D1, 18, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000751f8a65 6 bytes [68, C1, 5A, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000751fb17d 6 bytes [68, 5B, 5B, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000751fdb98 6 bytes [68, AD, 5B, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000752005ba 6 bytes [68, 72, DE, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000075200d32 6 bytes [68, F3, 59, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000075201218 6 bytes [68, 55, DC, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!EndPaint 0000000075201341 6 bytes [68, F7, 17, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000075201361 6 bytes [68, 87, 17, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000075202a8d 6 bytes [68, 23, DC, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!GetCapture 0000000075202aac 6 bytes [68, 83, DD, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000075203391 6 bytes [68, 37, 18, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!RegisterClassA 000000007520434b 6 bytes [68, 0E, 5B, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075205f74 6 bytes [68, 9D, DE, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000075206222 6 bytes [68, E3, 19, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!CallWindowProcA 000000007520792f 6 bytes [68, 3C, 5A, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000075207fbb 6 bytes [68, 1E, 59, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 000000007520810c 6 bytes [68, AD, 59, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000752085c1 6 bytes [68, D5, 58, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000752086b4 6 bytes [68, 67, 59, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007521d41f 6 bytes [68, 50, 19, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!ReleaseCapture 000000007521ed49 6 bytes [68, 33, DD, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!SetCapture 000000007521ed56 6 bytes [68, D9, DC, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000075239854 6 bytes [68, 9F, 57, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075239cfd 6 bytes [68, 9C, DC, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075239f1d 6 bytes [68, 54, 5F, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000752587cb 6 bytes [68, 4F, 57, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007570c592 6 bytes [68, B1, D3, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000075742538 6 bytes [68, 9A, D3, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075d23918 6 bytes [68, 27, E3, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075d24296 6 bytes [68, 38, DF, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075d24406 6 bytes [68, 80, E3, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WS2_32.dll!send 0000000075d26f01 6 bytes [68, 5F, E3, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075d37673 6 bytes [68, C8, DE, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000075841224 6 bytes [68, 89, 7E, 06, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000075b1c664 6 bytes [68, DC, 08, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000075b1e13a 6 bytes [68, 7C, 0A, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000075b1f8d8 6 bytes [68, 49, 09, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000075b23184 6 bytes [68, 50, 0A, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000075b45761 6 bytes [68, 1E, 06, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000075b45fef 6 bytes [68, DA, 05, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000075b4632d 6 bytes [68, 62, 06, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000075b4fa49 6 bytes [68, 77, 09, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000075b5f564 6 bytes [68, 0C, 07, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000075b5f639 6 bytes [68, 46, 08, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000075b74f2f 6 bytes [68, F6, 09, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000075b7525a 6 bytes [68, B7, 06, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000075bbece5 6 bytes [68, A9, 07, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe[3548] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000075bbedb7 6 bytes [68, 91, 08, 07, 02, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000778208fc 4 bytes [68, A0, CF, 26]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077820901 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000778325fd 6 bytes [68, BD, 57, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007783c45a 6 bytes [68, CB, D0, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077842a63 6 bytes [68, 03, 58, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077864128 6 bytes [68, 49, 58, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007786e659 6 bytes [68, 8F, 58, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007605455c 6 bytes [68, 34, D3, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000760579f8 6 bytes [68, F3, D2, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetDC 00000000751f72c4 4 bytes [68, 92, 18, 26]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000751f72c9 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000751f7446 6 bytes [68, 10, 19, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000751f7809 6 bytes [68, A5, 5D, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000751f78e2 6 bytes [68, 22, DE, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000751f7bd3 6 bytes [68, 4A, DE, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000751f8048 4 bytes [68, D1, 18, 26]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000751f804d 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000751f8a65 6 bytes [68, C1, 5A, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000751fb17d 6 bytes [68, 5B, 5B, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000751fdb98 6 bytes [68, AD, 5B, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000752005ba 6 bytes [68, 72, DE, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000075200d32 6 bytes [68, F3, 59, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000075201218 6 bytes [68, 55, DC, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!EndPaint 0000000075201341 4 bytes [68, F7, 17, 26]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!EndPaint + 5 0000000075201346 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000075201361 4 bytes [68, 87, 17, 26]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 0000000075201366 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000075202a8d 6 bytes [68, 23, DC, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetCapture 0000000075202aac 3 bytes [68, 83, DD]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetCapture + 4 0000000075202ab0 2 bytes [00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000075203391 4 bytes [68, 37, 18, 26]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 0000000075203396 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!RegisterClassA 000000007520434b 6 bytes [68, 0E, 5B, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075205f74 6 bytes [68, 9D, DE, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000075206222 6 bytes [68, E3, 19, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!CallWindowProcA 000000007520792f 6 bytes [68, 3C, 5A, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000075207fbb 6 bytes [68, 1E, 59, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 000000007520810c 6 bytes [68, AD, 59, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000752085c1 6 bytes [68, D5, 58, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000752086b4 6 bytes [68, 67, 59, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007521d41f 6 bytes [68, 50, 19, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!ReleaseCapture 000000007521ed49 6 bytes [68, 33, DD, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!SetCapture 000000007521ed56 4 bytes [68, D9, DC, 26]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!SetCapture + 5 000000007521ed5b 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000075239854 6 bytes [68, 9F, 57, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075239cfd 6 bytes [68, 9C, DC, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075239f1d 6 bytes [68, 54, 5F, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000752587cb 4 bytes [68, 4F, 57, 27]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 00000000752587d0 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007570c592 6 bytes [68, B1, D3, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000075742538 6 bytes [68, 9A, D3, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000075841224 6 bytes [68, 89, 7E, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075d23918 6 bytes [68, 27, E3, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075d24296 6 bytes [68, 38, DF, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075d24406 6 bytes [68, 80, E3, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WS2_32.dll!send 0000000075d26f01 6 bytes [68, 5F, E3, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075d37673 6 bytes [68, C8, DE, 26, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000075b1c664 6 bytes [68, DC, 08, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000075b1e13a 6 bytes [68, 7C, 0A, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000075b1f8d8 6 bytes [68, 49, 09, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000075b23184 6 bytes [68, 50, 0A, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000075b45761 6 bytes [68, 1E, 06, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000075b45fef 6 bytes [68, DA, 05, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000075b4632d 6 bytes [68, 62, 06, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000075b4fa49 6 bytes [68, 77, 09, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000075b5f564 6 bytes [68, 0C, 07, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000075b5f639 6 bytes [68, 46, 08, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000075b74f2f 6 bytes [68, F6, 09, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000075b7525a 6 bytes [68, B7, 06, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000075bbece5 6 bytes [68, A9, 07, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe[3568] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000075bbedb7 6 bytes [68, 91, 08, 27, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000778208fc 4 bytes [68, A0, CF, 24]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077820901 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000778325fd 6 bytes [68, BD, 57, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007783c45a 6 bytes [68, CB, D0, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077842a63 6 bytes [68, 03, 58, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077864128 6 bytes [68, 49, 58, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007786e659 6 bytes [68, 8F, 58, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007605455c 6 bytes [68, 34, D3, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000760579f8 6 bytes [68, F3, D2, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!GetDC 00000000751f72c4 4 bytes [68, 92, 18, 24]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000751f72c9 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000751f7446 6 bytes [68, 10, 19, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000751f7809 6 bytes [68, A5, 5D, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000751f78e2 6 bytes [68, 22, DE, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000751f7bd3 6 bytes [68, 4A, DE, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000751f8048 4 bytes [68, D1, 18, 24]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000751f804d 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000751f8a65 6 bytes [68, C1, 5A, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000751fb17d 6 bytes [68, 5B, 5B, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000751fdb98 6 bytes [68, AD, 5B, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000752005ba 6 bytes [68, 72, DE, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000075200d32 6 bytes [68, F3, 59, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000075201218 6 bytes [68, 55, DC, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!EndPaint 0000000075201341 4 bytes [68, F7, 17, 24]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!EndPaint + 5 0000000075201346 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000075201361 4 bytes [68, 87, 17, 24]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 0000000075201366 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000075202a8d 6 bytes [68, 23, DC, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!GetCapture 0000000075202aac 6 bytes [68, 83, DD, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000075203391 4 bytes [68, 37, 18, 24]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 0000000075203396 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!RegisterClassA 000000007520434b 6 bytes [68, 0E, 5B, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075205f74 6 bytes [68, 9D, DE, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000075206222 6 bytes [68, E3, 19, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!CallWindowProcA 000000007520792f 6 bytes [68, 3C, 5A, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000075207fbb 6 bytes [68, 1E, 59, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 000000007520810c 6 bytes [68, AD, 59, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000752085c1 6 bytes [68, D5, 58, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000752086b4 6 bytes [68, 67, 59, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007521d41f 6 bytes [68, 50, 19, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!ReleaseCapture 000000007521ed49 6 bytes [68, 33, DD, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!SetCapture 000000007521ed56 4 bytes [68, D9, DC, 24]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!SetCapture + 5 000000007521ed5b 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000075239854 6 bytes [68, 9F, 57, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075239cfd 6 bytes [68, 9C, DC, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075239f1d 6 bytes [68, 54, 5F, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000752587cb 4 bytes [68, 4F, 57, 25]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 00000000752587d0 1 byte [C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007570c592 6 bytes [68, B1, D3, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000075742538 6 bytes [68, 9A, D3, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075d23918 6 bytes [68, 27, E3, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075d24296 6 bytes [68, 38, DF, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075d24406 6 bytes [68, 80, E3, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WS2_32.dll!send 0000000075d26f01 6 bytes [68, 5F, E3, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075d37673 6 bytes [68, C8, DE, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000075841224 6 bytes [68, 89, 7E, 24, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000075b1c664 6 bytes [68, DC, 08, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000075b1e13a 6 bytes [68, 7C, 0A, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000075b1f8d8 6 bytes [68, 49, 09, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000075b23184 6 bytes [68, 50, 0A, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000075b45761 6 bytes [68, 1E, 06, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000075b45fef 6 bytes [68, DA, 05, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000075b4632d 6 bytes [68, 62, 06, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000075b4fa49 6 bytes [68, 77, 09, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000075b5f564 6 bytes [68, 0C, 07, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000075b5f639 6 bytes [68, 46, 08, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000075b74f2f 6 bytes [68, F6, 09, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000075b7525a 6 bytes [68, B7, 06, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000075bbece5 6 bytes [68, A9, 07, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe[3580] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000075bbedb7 6 bytes [68, 91, 08, 25, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000778208fc 4 bytes [68, A0, CF, 6C]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077820901 1 byte [C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000778325fd 6 bytes [68, BD, 57, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007783c45a 6 bytes [68, CB, D0, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077842a63 6 bytes [68, 03, 58, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077864128 6 bytes [68, 49, 58, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007786e659 6 bytes [68, 8F, 58, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007605455c 6 bytes [68, 34, D3, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000760579f8 6 bytes [68, F3, D2, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075d23918 6 bytes [68, 27, E3, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075d24296 6 bytes [68, 38, DF, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075d24406 6 bytes [68, 80, E3, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WS2_32.dll!send 0000000075d26f01 6 bytes [68, 5F, E3, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075d37673 6 bytes [68, C8, DE, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!GetDC 00000000751f72c4 4 bytes [68, 92, 18, 6C]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000751f72c9 1 byte [C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000751f7446 6 bytes [68, 10, 19, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000751f7809 6 bytes [68, A5, 5D, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000751f78e2 6 bytes [68, 22, DE, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000751f7bd3 6 bytes [68, 4A, DE, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000751f8048 4 bytes [68, D1, 18, 6C]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000751f804d 1 byte [C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000751f8a65 6 bytes [68, C1, 5A, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000751fb17d 6 bytes [68, 5B, 5B, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000751fdb98 6 bytes [68, AD, 5B, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000752005ba 6 bytes [68, 72, DE, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000075200d32 6 bytes [68, F3, 59, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000075201218 6 bytes [68, 55, DC, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!EndPaint 0000000075201341 4 bytes [68, F7, 17, 6C]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!EndPaint + 5 0000000075201346 1 byte [C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000075201361 4 bytes [68, 87, 17, 6C]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 0000000075201366 1 byte [C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000075202a8d 6 bytes [68, 23, DC, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!GetCapture 0000000075202aac 6 bytes [68, 83, DD, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000075203391 4 bytes [68, 37, 18, 6C]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 0000000075203396 1 byte [C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!RegisterClassA 000000007520434b 6 bytes [68, 0E, 5B, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075205f74 6 bytes [68, 9D, DE, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000075206222 6 bytes [68, E3, 19, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!CallWindowProcA 000000007520792f 6 bytes [68, 3C, 5A, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000075207fbb 6 bytes [68, 1E, 59, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 000000007520810c 6 bytes [68, AD, 59, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000752085c1 6 bytes [68, D5, 58, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000752086b4 6 bytes [68, 67, 59, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007521d41f 6 bytes [68, 50, 19, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!ReleaseCapture 000000007521ed49 6 bytes [68, 33, DD, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!SetCapture 000000007521ed56 4 bytes [68, D9, DC, 6C]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!SetCapture + 5 000000007521ed5b 1 byte [C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000075239854 6 bytes [68, 9F, 57, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075239cfd 6 bytes [68, 9C, DC, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075239f1d 6 bytes [68, 54, 5F, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000752587cb 4 bytes [68, 4F, 57, 6D]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 00000000752587d0 1 byte [C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007570c592 6 bytes [68, B1, D3, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000075742538 6 bytes [68, 9A, D3, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000075841224 6 bytes [68, 89, 7E, 6C, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000075b1c664 6 bytes [68, DC, 08, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000075b1e13a 6 bytes [68, 7C, 0A, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000075b1f8d8 6 bytes [68, 49, 09, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000075b23184 6 bytes [68, 50, 0A, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000075b45761 6 bytes [68, 1E, 06, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000075b45fef 6 bytes [68, DA, 05, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000075b4632d 6 bytes [68, 62, 06, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000075b4fa49 6 bytes [68, 77, 09, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000075b5f564 6 bytes [68, 0C, 07, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000075b5f639 6 bytes [68, 46, 08, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000075b74f2f 6 bytes [68, F6, 09, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000075b7525a 6 bytes [68, B7, 06, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000075bbece5 6 bytes [68, A9, 07, 6D, 00, C3]
.text C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe[3588] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000075bbedb7 6 bytes [68, 91, 08, 6D, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000778208fc 4 bytes [68, A0, CF, 1A]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077820901 1 byte [C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000778325fd 6 bytes [68, BD, 57, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007783c45a 6 bytes [68, CB, D0, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077842a63 6 bytes [68, 03, 58, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077864128 6 bytes [68, 49, 58, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007786e659 6 bytes [68, 8F, 58, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007605455c 6 bytes [68, 34, D3, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000760579f8 6 bytes [68, F3, D2, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!GetDC 00000000751f72c4 4 bytes [68, 92, 18, 1A]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000751f72c9 1 byte [C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000751f7446 6 bytes [68, 10, 19, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000751f7809 6 bytes [68, A5, 5D, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000751f78e2 6 bytes [68, 22, DE, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000751f7bd3 6 bytes [68, 4A, DE, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000751f8048 4 bytes [68, D1, 18, 1A]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000751f804d 1 byte [C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000751f8a65 6 bytes [68, C1, 5A, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000751fb17d 6 bytes [68, 5B, 5B, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000751fdb98 6 bytes [68, AD, 5B, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000752005ba 6 bytes [68, 72, DE, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000075200d32 6 bytes [68, F3, 59, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000075201218 6 bytes [68, 55, DC, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!EndPaint 0000000075201341 4 bytes [68, F7, 17, 1A]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!EndPaint + 5 0000000075201346 1 byte [C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000075201361 4 bytes [68, 87, 17, 1A]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 0000000075201366 1 byte [C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000075202a8d 6 bytes [68, 23, DC, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!GetCapture 0000000075202aac 6 bytes [68, 83, DD, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000075203391 4 bytes [68, 37, 18, 1A]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 0000000075203396 1 byte [C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!RegisterClassA 000000007520434b 6 bytes [68, 0E, 5B, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075205f74 6 bytes [68, 9D, DE, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000075206222 6 bytes [68, E3, 19, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!CallWindowProcA 000000007520792f 6 bytes [68, 3C, 5A, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000075207fbb 6 bytes [68, 1E, 59, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 000000007520810c 6 bytes [68, AD, 59, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000752085c1 6 bytes [68, D5, 58, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000752086b4 6 bytes [68, 67, 59, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007521d41f 6 bytes [68, 50, 19, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!ReleaseCapture 000000007521ed49 6 bytes [68, 33, DD, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!SetCapture 000000007521ed56 4 bytes [68, D9, DC, 1A]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!SetCapture + 5 000000007521ed5b 1 byte [C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000075239854 6 bytes [68, 9F, 57, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075239cfd 6 bytes [68, 9C, DC, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075239f1d 6 bytes [68, 54, 5F, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000752587cb 4 bytes [68, 4F, 57, 1B]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 00000000752587d0 1 byte [C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007570c592 6 bytes [68, B1, D3, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000075742538 6 bytes [68, 9A, D3, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000075b1c664 6 bytes [68, DC, 08, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000075b1e13a 6 bytes [68, 7C, 0A, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000075b1f8d8 6 bytes [68, 49, 09, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000075b23184 6 bytes [68, 50, 0A, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000075b45761 6 bytes [68, 1E, 06, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000075b45fef 6 bytes [68, DA, 05, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000075b4632d 6 bytes [68, 62, 06, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000075b4fa49 6 bytes [68, 77, 09, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000075b5f564 6 bytes [68, 0C, 07, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000075b5f639 6 bytes [68, 46, 08, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000075b74f2f 6 bytes [68, F6, 09, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000075b7525a 6 bytes [68, B7, 06, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000075bbece5 6 bytes [68, A9, 07, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000075bbedb7 6 bytes [68, 91, 08, 1B, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000075841224 6 bytes [68, 89, 7E, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075d23918 6 bytes [68, 27, E3, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075d24296 6 bytes [68, 38, DF, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075d24406 6 bytes [68, 80, E3, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WS2_32.dll!send 0000000075d26f01 6 bytes [68, 5F, E3, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075d37673 6 bytes [68, C8, DE, 1A, 00, C3]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000752e1465 2 bytes [2E, 75]
.text C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe[4068] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000752e14bb 2 bytes [2E, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000778208fc 4 bytes [68, A0, CF, 1A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077820901 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000778325fd 6 bytes [68, BD, 57, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007783c45a 6 bytes [68, CB, D0, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077842a63 6 bytes [68, 03, 58, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077864128 6 bytes [68, 49, 58, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007786e659 6 bytes [68, 8F, 58, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007605455c 6 bytes [68, 34, D3, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000760579f8 6 bytes [68, F3, D2, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007570c592 6 bytes [68, B1, D3, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000075742538 6 bytes [68, 9A, D3, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!GetDC 00000000751f72c4 4 bytes [68, 92, 18, 1A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000751f72c9 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000751f7446 6 bytes [68, 10, 19, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000751f7809 6 bytes [68, A5, 5D, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000751f78e2 6 bytes [68, 22, DE, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000751f7bd3 6 bytes [68, 4A, DE, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000751f8048 4 bytes [68, D1, 18, 1A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000751f804d 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000751f8a65 6 bytes [68, C1, 5A, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000751fb17d 6 bytes [68, 5B, 5B, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000751fdb98 6 bytes [68, AD, 5B, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000752005ba 6 bytes [68, 72, DE, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000075200d32 6 bytes [68, F3, 59, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000075201218 6 bytes [68, 55, DC, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!EndPaint 0000000075201341 4 bytes [68, F7, 17, 1A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!EndPaint + 5 0000000075201346 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000075201361 4 bytes [68, 87, 17, 1A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 0000000075201366 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000075202a8d 6 bytes [68, 23, DC, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!GetCapture 0000000075202aac 6 bytes [68, 83, DD, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000075203391 4 bytes [68, 37, 18, 1A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 0000000075203396 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!RegisterClassA 000000007520434b 6 bytes [68, 0E, 5B, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075205f74 6 bytes [68, 9D, DE, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000075206222 6 bytes [68, E3, 19, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!CallWindowProcA 000000007520792f 6 bytes [68, 3C, 5A, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000075207fbb 6 bytes [68, 1E, 59, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 000000007520810c 6 bytes [68, AD, 59, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000752085c1 6 bytes [68, D5, 58, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000752086b4 6 bytes [68, 67, 59, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007521d41f 6 bytes [68, 50, 19, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!ReleaseCapture 000000007521ed49 6 bytes [68, 33, DD, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!SetCapture 000000007521ed56 4 bytes [68, D9, DC, 1A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!SetCapture + 5 000000007521ed5b 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000075239854 6 bytes [68, 9F, 57, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000075239cfd 6 bytes [68, 9C, DC, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000075239f1d 6 bytes [68, 54, 5F, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000752587cb 4 bytes [68, 4F, 57, 1B]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 00000000752587d0 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000075b1c664 6 bytes [68, DC, 08, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000075b1e13a 6 bytes [68, 7C, 0A, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000075b1f8d8 6 bytes [68, 49, 09, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000075b23184 6 bytes [68, 50, 0A, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000075b45761 6 bytes [68, 1E, 06, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000075b45fef 6 bytes [68, DA, 05, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000075b4632d 6 bytes [68, 62, 06, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000075b4fa49 6 bytes [68, 77, 09, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000075b5f564 6 bytes [68, 0C, 07, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000075b5f639 6 bytes [68, 46, 08, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000075b74f2f 6 bytes [68, F6, 09, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000075b7525a 6 bytes [68, B7, 06, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000075bbece5 6 bytes [68, A9, 07, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000075bbedb7 6 bytes [68, 91, 08, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075d23918 6 bytes [68, 27, E3, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075d24296 6 bytes [68, 38, DF, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075d24406 6 bytes [68, 80, E3, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WS2_32.dll!send 0000000075d26f01 6 bytes [68, 5F, E3, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075d37673 6 bytes [68, C8, DE, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000075841224 6 bytes [68, 89, 7E, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000752e1465 2 bytes [2E, 75]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000752e14bb 2 bytes [2E, 75]
.text ... |