Gmer-Log Aufgeteilt, Teil 1 Code:
GMER 2.1.19355 - hxxp://www.gmer.net
Rootkit scan 2014-01-24 10:07:27
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD50 rev.01.0 465,76GB
Running: gmer.exe; Driver: C:\Users\x\AppData\Local\Temp\ugldipow.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000077a9af40 7 bytes JMP 000000016fff0260
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077aa4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000077ac2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077acefe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077af99b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077b094d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077b09640 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077b2a500 7 bytes JMP 000000016fff0228
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdbe2db0 5 bytes JMP 000007fffdbd0180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdbe37d0 7 bytes JMP 000007fffdbd00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdbe8ef0 6 bytes JMP 000007fffdbd0148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdbfaf60 5 bytes JMP 000007fffdbd0110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8e89e0 8 bytes JMP 000007fffdbd01f0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8ebe40 8 bytes JMP 000007fffdbd01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe117490 11 bytes JMP 000007fffdbd0228
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1652] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe12bf00 7 bytes JMP 000007fffdbd0260
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000077a9af40 7 bytes JMP 000000016fff0260
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077aa4a60 5 bytes JMP 000000016fff01b8
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000077ac2990 5 bytes JMP 000000016fff01f0
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077acefe0 5 bytes JMP 000000016fff0148
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077af99b0 7 bytes JMP 000000016fff00d8
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077b094d0 5 bytes JMP 000000016fff0180
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077b09640 5 bytes JMP 000000016fff0110
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077b2a500 7 bytes JMP 000000016fff0228
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdbe2db0 5 bytes JMP 000007fffdbd0180
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdbe37d0 7 bytes JMP 000007fffdbd00d8
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdbe8ef0 6 bytes JMP 000007fffdbd0148
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdbfaf60 5 bytes JMP 000007fffdbd0110
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8e89e0 8 bytes JMP 000007fffdbd01f0
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8ebe40 8 bytes JMP 000007fffdbd01b8
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\dxgi.dll!CreateDXGIFactory 000007fef8f6dc88 5 bytes JMP 000007fff8d600d8
.text C:\Windows\system32\Dwm.exe[1908] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1 000007fef8f6de10 5 bytes JMP 000007fff8d60110
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000077a9af40 7 bytes JMP 000000016fff0260
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077aa4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000077ac2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077acefe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077af99b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077b094d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077b09640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077b2a500 7 bytes JMP 000000016fff0228
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdbe2db0 5 bytes JMP 000007fffdbd0180
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdbe37d0 7 bytes JMP 000007fffdbd00d8
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdbe8ef0 6 bytes JMP 000007fffdbd0148
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdbfaf60 5 bytes JMP 000007fffdbd0110
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8e89e0 8 bytes JMP 000007fffdbd01f0
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8ebe40 8 bytes JMP 000007fffdbd01b8
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe117490 11 bytes JMP 000007fffdbd0228
.text C:\Program Files\Elantech\ETDCtrl.exe[2328] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe12bf00 7 bytes JMP 000007fffdbd0260
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000077a9af40 7 bytes JMP 000000016fff0260
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077aa4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000077ac2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077acefe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077af99b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077b094d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077b09640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077b2a500 7 bytes JMP 000000016fff0228
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdbe2db0 5 bytes JMP 000007fffdbd0180
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdbe37d0 7 bytes JMP 000007fffdbd00d8
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdbe8ef0 6 bytes JMP 000007fffdbd0148
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdbfaf60 5 bytes JMP 000007fffdbd0110
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8e89e0 8 bytes JMP 000007fffdbd01f0
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8ebe40 8 bytes JMP 000007fffdbd01b8
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe117490 11 bytes JMP 000007fffdbd0228
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[2336] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe12bf00 7 bytes JMP 000007fffdbd0260
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000077a9af40 7 bytes JMP 000000016fff0260
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077aa4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000077ac2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077acefe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077af99b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077b094d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077b09640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077b2a500 7 bytes JMP 000000016fff0228
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdbe2db0 5 bytes JMP 000007fffdbd0180
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdbe37d0 7 bytes JMP 000007fffdbd00d8
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdbe8ef0 6 bytes JMP 000007fffdbd0148
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdbfaf60 5 bytes JMP 000007fffdbd0110
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe117490 11 bytes JMP 000007fffdbd0228
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe12bf00 7 bytes JMP 000007fffdbd0260
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8e89e0 8 bytes JMP 000007fffdbd01f0
.text C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[2344] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8ebe40 8 bytes JMP 000007fffdbd01b8
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000077a9af40 7 bytes JMP 000000016fff0260
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077aa4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000077ac2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077acefe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077af99b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077b094d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077b09640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077b2a500 7 bytes JMP 000000016fff0228
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdbe2db0 5 bytes JMP 000007fffdbd0180
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdbe37d0 7 bytes JMP 000007fffdbd00d8
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdbe8ef0 6 bytes JMP 000007fffdbd0148
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdbfaf60 5 bytes JMP 000007fffdbd0110
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8e89e0 8 bytes JMP 000007fffdbd01f0
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8ebe40 8 bytes JMP 000007fffdbd01b8
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe117490 11 bytes JMP 000007fffdbd0228
.text C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe[2380] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe12bf00 7 bytes JMP 000007fffdbd0260
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000075961eee 7 bytes JMP 00000001709f16b3
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000075965b85 7 bytes JMP 00000001709f11cc
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000759713e1 7 bytes JMP 00000001709f12a8
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 000000007597ea0d 7 bytes JMP 00000001709f1262
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007598b1d3 5 bytes JMP 00000001709f15c8
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000075a088b4 7 bytes JMP 00000001709f1357
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000075a08939 5 bytes JMP 00000001709f16f4
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000075a08c8f 5 bytes JMP 00000001709f101e
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076d81d1b 5 bytes JMP 00000001709f11e5
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076d81dc9 5 bytes JMP 00000001709f1019
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076d82aa4 5 bytes JMP 00000001709f1573
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076d82d0a 5 bytes JMP 00000001709f128f
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075868a29 5 bytes JMP 00000001709f1046
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075874572 5 bytes JMP 00000001709f10c8
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007588e567 5 bytes JMP 00000001709f1433
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000758c7a5c 5 bytes JMP 00000001709f15f0
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076c9e96b 5 bytes JMP 00000001709f15e1
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076c9eba5 5 bytes JMP 00000001709f11a9
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075bd5ea5 5 bytes JMP 00000001709f1618
.text C:\Program Files (x86)\Launch Manager\LMworker.exe[2468] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075c09d0b 5 bytes JMP 00000001709f123f
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000075961eee 7 bytes JMP 00000001709f16b3
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000075965b85 7 bytes JMP 00000001709f11cc
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000759713e1 7 bytes JMP 00000001709f12a8
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 000000007597ea0d 7 bytes JMP 00000001709f1262
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007598b1d3 5 bytes JMP 00000001709f15c8
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000075a088b4 7 bytes JMP 00000001709f1357
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000075a08939 5 bytes JMP 00000001709f16f4
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000075a08c8f 5 bytes JMP 00000001709f101e
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076d81d1b 5 bytes JMP 00000001709f11e5
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076d81dc9 5 bytes JMP 00000001709f1019
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076d82aa4 5 bytes JMP 00000001709f1573
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076d82d0a 5 bytes JMP 00000001709f128f
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075868a29 5 bytes JMP 00000001709f1046
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075874572 5 bytes JMP 00000001709f10c8
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007588e567 5 bytes JMP 00000001709f1433
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000758c7a5c 5 bytes JMP 00000001709f15f0
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076c9e96b 5 bytes JMP 00000001709f15e1
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076c9eba5 5 bytes JMP 00000001709f11a9
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075bd5ea5 5 bytes JMP 00000001709f1618
.text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2476] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075c09d0b 5 bytes JMP 00000001709f123f
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000075961eee 7 bytes JMP 00000001709f16b3
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000075965b85 7 bytes JMP 00000001709f11cc
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000759713e1 7 bytes JMP 00000001709f12a8
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 000000007597ea0d 7 bytes JMP 00000001709f1262
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007598b1d3 5 bytes JMP 00000001709f15c8
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000075a088b4 7 bytes JMP 00000001709f1357
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000075a08939 5 bytes JMP 00000001709f16f4
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000075a08c8f 5 bytes JMP 00000001709f101e
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076d81d1b 5 bytes JMP 00000001709f11e5
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076d81dc9 5 bytes JMP 00000001709f1019
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076d82aa4 5 bytes JMP 00000001709f1573
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076d82d0a 5 bytes JMP 00000001709f128f
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076c9e96b 5 bytes JMP 00000001709f15e1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076c9eba5 5 bytes JMP 00000001709f11a9
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075868a29 5 bytes JMP 00000001709f1046
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075874572 5 bytes JMP 00000001709f10c8
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007588e567 5 bytes JMP 00000001709f1433
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000758c7a5c 5 bytes JMP 00000001709f15f0
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075bd5ea5 5 bytes JMP 00000001709f1618
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2660] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075c09d0b 5 bytes JMP 00000001709f123f
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[2672] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000077a9af40 7 bytes JMP 000000016fff0260
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[2672] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077aa4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[2672] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000077ac2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[2672] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077acefe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[2672] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077af99b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[2672] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077b094d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[2672] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077b09640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[2672] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077b2a500 7 bytes JMP 000000016fff0228
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[2672] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdbe2db0 5 bytes JMP 000007fffdbd0180
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[2672] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdbe37d0 7 bytes JMP 000007fffdbd00d8
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[2672] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdbe8ef0 6 bytes JMP 000007fffdbd0148
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[2672] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdbfaf60 5 bytes JMP 000007fffdbd0110
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[2672] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8e89e0 8 bytes JMP 000007fffdbd01f0
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[2672] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8ebe40 8 bytes JMP 000007fffdbd01b8
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\KERNEL32.dll!RegSetValueExW 0000000077a9af40 7 bytes JMP 000000016fff0260
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW 0000000077aa4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW 0000000077ac2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 0000000077acefe0 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 0000000077af99b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 0000000077b094d0 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\KERNEL32.dll!K32GetModuleFileNameExW 0000000077b09640 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 0000000077b2a500 7 bytes JMP 000000016fff0228
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdbe2db0 5 bytes JMP 000007fffdbd0180
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdbe37d0 7 bytes JMP 000007fffdbd00d8
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdbe8ef0 6 bytes JMP 000007fffdbd0148
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdbfaf60 5 bytes JMP 000007fffdbd0110
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8e89e0 8 bytes JMP 000007fffdbd01f0
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8ebe40 8 bytes JMP 000007fffdbd01b8
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe117490 11 bytes JMP 000007fffdbd0228
.text C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe[2680] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe12bf00 7 bytes JMP 000007fffdbd0260
.text C:\Program Files\Rainmeter\Rainmeter.exe[2696] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000077a9af40 7 bytes JMP 000000016fff0260
.text C:\Program Files\Rainmeter\Rainmeter.exe[2696] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077aa4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Rainmeter\Rainmeter.exe[2696] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000077ac2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files\Rainmeter\Rainmeter.exe[2696] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077acefe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Rainmeter\Rainmeter.exe[2696] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077af99b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Rainmeter\Rainmeter.exe[2696] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077b094d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Rainmeter\Rainmeter.exe[2696] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077b09640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Rainmeter\Rainmeter.exe[2696] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077b2a500 7 bytes JMP 000000016fff0228
.text C:\Program Files\Rainmeter\Rainmeter.exe[2696] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdbe2db0 5 bytes JMP 000007fffdbd0180
.text C:\Program Files\Rainmeter\Rainmeter.exe[2696] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdbe37d0 7 bytes JMP 000007fffdbd00d8
.text C:\Program Files\Rainmeter\Rainmeter.exe[2696] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdbe8ef0 6 bytes JMP 000007fffdbd0148
.text C:\Program Files\Rainmeter\Rainmeter.exe[2696] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdbfaf60 5 bytes JMP 000007fffdbd0110
.text C:\Program Files\Rainmeter\Rainmeter.exe[2696] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8e89e0 8 bytes JMP 000007fffdbd01f0
.text C:\Program Files\Rainmeter\Rainmeter.exe[2696] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8ebe40 8 bytes JMP 000007fffdbd01b8
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000075961eee 7 bytes JMP 00000001709f16b3
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000075965b85 7 bytes JMP 00000001709f11cc
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000759713e1 7 bytes JMP 00000001709f12a8
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 000000007597ea0d 7 bytes JMP 00000001709f1262
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007598b1d3 5 bytes JMP 00000001709f15c8
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000075a088b4 7 bytes JMP 00000001709f1357
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000075a08939 5 bytes JMP 00000001709f16f4
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000075a08c8f 5 bytes JMP 00000001709f101e
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076d81d1b 5 bytes JMP 00000001709f11e5
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076d81dc9 5 bytes JMP 00000001709f1019
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076d82aa4 5 bytes JMP 00000001709f1573
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076d82d0a 5 bytes JMP 00000001709f128f
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076c9e96b 5 bytes JMP 00000001709f15e1
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076c9eba5 5 bytes JMP 00000001709f11a9
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075868a29 5 bytes JMP 00000001709f1046
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075874572 5 bytes JMP 00000001709f10c8
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007588e567 5 bytes JMP 00000001709f1433
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000758c7a5c 5 bytes JMP 00000001709f15f0
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075bd5ea5 5 bytes JMP 00000001709f1618
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075c09d0b 5 bytes JMP 00000001709f123f
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000077d61465 2 bytes [D6, 77]
.text C:\Program Files (x86)\Launch Manager\LManager.exe[2888] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000077d614bb 2 bytes [D6, 77]
.text ... * 2
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 0000000075961eee 7 bytes JMP 00000001709f16b3
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 0000000075965b85 7 bytes JMP 00000001709f11cc
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000759713e1 7 bytes JMP 00000001709f12a8
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 000000007597ea0d 7 bytes JMP 00000001709f1262
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007598b1d3 5 bytes JMP 00000001709f15c8
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000075a088b4 7 bytes JMP 00000001709f1357
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000075a08939 5 bytes JMP 00000001709f16f4
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000075a08c8f 5 bytes JMP 00000001709f101e
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076d81d1b 5 bytes JMP 00000001709f11e5
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076d81dc9 5 bytes JMP 00000001709f1019
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076d82aa4 5 bytes JMP 00000001709f1573
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076d82d0a 5 bytes JMP 00000001709f128f
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076c9e96b 5 bytes JMP 00000001709f15e1
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076c9eba5 5 bytes JMP 00000001709f11a9
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075868a29 5 bytes JMP 00000001709f1046
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075874572 5 bytes JMP 00000001709f10c8
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007588e567 5 bytes JMP 00000001709f1433
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000758c7a5c 5 bytes JMP 00000001709f15f0
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075bd5ea5 5 bytes JMP 00000001709f1618
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2896] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075c09d0b 5 bytes JMP 00000001709f123f
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[2924] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000077a9af40 7 bytes JMP 000000016fff0260
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[2924] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077aa4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[2924] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000077ac2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[2924] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077acefe0 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[2924] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077af99b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[2924] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077b094d0 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[2924] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077b09640 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[2924] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077b2a500 7 bytes JMP 000000016fff0228
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[2924] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdbe2db0 5 bytes JMP 000007fffdbd0180
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[2924] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdbe37d0 7 bytes JMP 000007fffdbd00d8
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[2924] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdbe8ef0 6 bytes JMP 000007fffdbd0148
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[2924] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdbfaf60 5 bytes JMP 000007fffdbd0110
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[2924] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8e89e0 8 bytes JMP 000007fffdbd01f0
.text C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[2924] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8ebe40 8 bytes JMP 000007fffdbd01b8
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000077a9af40 7 bytes JMP 000000016fff0260
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077aa4a60 5 bytes JMP 000000016fff01b8
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000077ac2990 5 bytes JMP 000000016fff01f0
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077acefe0 5 bytes JMP 000000016fff0148
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077af99b0 7 bytes JMP 000000016fff00d8
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077b094d0 5 bytes JMP 000000016fff0180
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077b09640 5 bytes JMP 000000016fff0110
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077b2a500 7 bytes JMP 000000016fff0228
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdbe2db0 5 bytes JMP 000007fffdbd0180
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdbe37d0 7 bytes JMP 000007fffdbd00d8
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdbe8ef0 6 bytes JMP 000007fffdbd0148
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdbfaf60 5 bytes JMP 000007fffdbd0110
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe117490 11 bytes JMP 000007fffdbd0228
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe12bf00 7 bytes JMP 000007fffdbd0260
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8e89e0 8 bytes JMP 000007fffdbd01f0
.text C:\Windows\system32\wbem\unsecapp.exe[3412] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8ebe40 8 bytes JMP 000007fffdbd01b8
.text C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[3496] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000077a9af40 7 bytes JMP 000000016fff0260
.text C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[3496] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077aa4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[3496] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000077ac2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[3496] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000077acefe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[3496] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077af99b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[3496] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077b094d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[3496] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077b09640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[3496] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077b2a500 7 bytes JMP 000000016fff0228
.text C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[3496] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdbe2db0 5 bytes JMP 000007fffdbd0180
.text C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[3496] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdbe37d0 7 bytes JMP 000007fffdbd00d8
.text C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[3496] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdbe8ef0 6 bytes JMP 000007fffdbd0148
.text C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[3496] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdbfaf60 5 bytes JMP 000007fffdbd0110
.text C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[3496] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8e89e0 8 bytes JMP 000007fffdbd01f0
.text C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe[3496] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8ebe40 8 bytes JMP 000007fffdbd01b8
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW 0000000075961eee 7 bytes JMP 00000001709f16b3
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW 0000000075965b85 7 bytes JMP 00000001709f11cc
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA 00000000759713e1 7 bytes JMP 00000001709f12a8
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW 000000007597ea0d 7 bytes JMP 00000001709f1262
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleFileNameExW 000000007598b1d3 5 bytes JMP 00000001709f15c8
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx 0000000075a088b4 7 bytes JMP 00000001709f1357
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation 0000000075a08939 5 bytes JMP 00000001709f16f4
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW 0000000075a08c8f 5 bytes JMP 00000001709f101e
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000076d81d1b 5 bytes JMP 00000001709f11e5
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000076d81dc9 5 bytes JMP 00000001709f1019
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000076d82aa4 5 bytes JMP 00000001709f1573
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000076d82d0a 5 bytes JMP 00000001709f128f
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076c9e96b 5 bytes JMP 00000001709f15e1
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076c9eba5 5 bytes JMP 00000001709f11a9
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075868a29 5 bytes JMP 00000001709f1046
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075874572 5 bytes JMP 00000001709f10c8
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007588e567 5 bytes JMP 00000001709f1433
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 00000000758c7a5c 5 bytes JMP 00000001709f15f0
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000075bd5ea5 5 bytes JMP 00000001709f1618
.text C:\Program Files (x86)\DisplayFusion\DisplayFusionAppHook.exe[3612] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000075c09d0b 5 bytes JMP 00000001709f123f
.text C:\Program Files\Sandboxie\SbieSvc.exe[4964] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdbe2db0 5 bytes JMP 000007fffdbd0180
.text C:\Program Files\Sandboxie\SbieSvc.exe[4964] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdbe37d0 7 bytes JMP 000007fffdbd00d8
.text C:\Program Files\Sandboxie\SbieSvc.exe[4964] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdbe8ef0 6 bytes JMP 000007fffdbd0148
.text C:\Program Files\Sandboxie\SbieSvc.exe[4964] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdbfaf60 5 bytes JMP 000007fffdbd0110
.text C:\Program Files\Sandboxie\SbieSvc.exe[4964] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8e89e0 8 bytes JMP 000007fffdbd01f0
.text C:\Program Files\Sandboxie\SbieSvc.exe[4964] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8ebe40 8 bytes JMP 000007fffdbd01b8
.text C:\Program Files\Sandboxie\SbieSvc.exe[4964] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 0000000077996c80 5 bytes JMP 000000016fff0308
.text C:\Program Files\Sandboxie\SbieSvc.exe[4964] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000000007799a5b4 5 bytes JMP 000000016fff02d0
.text C:\Program Files\Sandboxie\SbieSvc.exe[4964] C:\Windows\system32\USER32.dll!CreateWindowExW 00000000779a0810 7 bytes JMP 000000016fff0340
.text C:\Program Files\Sandboxie\SbieSvc.exe[4964] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 00000000779accec 9 bytes JMP 000000016fff0298
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!RtlAdjustPrivilege 0000000077bba7d0 5 bytes JMP 0000000100cd26ac
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077bd3b10 5 bytes JMP 0000000175750720
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077bd7ac0 5 bytes JMP 0000000175750680
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!LdrInitializeThunk 0000000077bdc340 5 bytes JMP 0000000077d60008
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx 0000000077be92d0 5 bytes JMP 0000000175752e00
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!RtlGetCurrentDirectory_U 0000000077bfb130 5 bytes JMP 0000000175730a90
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!RtlSetCurrentDirectory_U 0000000077bfb470 5 bytes JMP 0000000175730d20
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryElevationFlags 0000000077bfb870 5 bytes JMP 000000017575ddb0
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!LdrQueryImageFileExecutionOptions 0000000077bfbb60 5 bytes JMP 00000001757507e0
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtMapUserPhysicalPagesScatter 0000000077c012e0 4 bytes [49, C7, C2, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtMapUserPhysicalPagesScatter + 7 0000000077c012e7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtWaitForSingleObject 0000000077c012f0 5 bytes [49, C7, C2, 01, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtWaitForSingleObject + 7 0000000077c012f7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReadFile 0000000077c01310 5 bytes JMP 0000000175726850
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReadFile + 7 0000000077c01317 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtDeviceIoControlFile 0000000077c01320 1 byte JMP 000000017572fcb0
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtDeviceIoControlFile + 2 0000000077c01322 3 bytes JMP 0000000077c110d9
.text ... * 2
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtWriteFile 0000000077c01330 5 bytes JMP 0000000175726970
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtWriteFile + 7 0000000077c01337 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtRemoveIoCompletion 0000000077c01340 5 bytes [49, C7, C2, 06, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtRemoveIoCompletion + 7 0000000077c01347 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReleaseSemaphore 0000000077c01350 5 bytes [49, C7, C2, 07, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReleaseSemaphore + 7 0000000077c01357 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c01360 5 bytes [49, C7, C2, 08, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort + 7 0000000077c01367 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReplyPort 0000000077c01370 5 bytes [49, C7, C2, 09, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReplyPort + 7 0000000077c01377 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077c01380 5 bytes [49, C7, C2, 0A, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread + 7 0000000077c01387 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetEvent 0000000077c01390 5 bytes [49, C7, C2, 0B, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetEvent + 7 0000000077c01397 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtClose 0000000077c013a0 5 bytes JMP 0000000175732f80
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtClose + 7 0000000077c013a7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c013b0 1 byte JMP 0000000175752340
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject + 2 0000000077c013b2 3 bytes {JMP 0xfffffffffdb50f90}
.text ... * 2
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationFile 0000000077c013c0 5 bytes JMP 00000001757354e0
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationFile + 7 0000000077c013c7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey 0000000077c013d0 5 bytes JMP 000000017574f350
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenKey + 7 0000000077c013d7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtEnumerateValueKey 0000000077c013e0 1 byte JMP 000000017574ee70
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtEnumerateValueKey + 2 0000000077c013e2 3 bytes {JMP 0xfffffffffdb4da90}
.text ... * 2
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtFindAtom 0000000077c013f0 5 bytes [49, C7, C2, 11, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtFindAtom + 7 0000000077c013f7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryDefaultLocale 0000000077c01400 5 bytes [49, C7, C2, 12, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryDefaultLocale + 7 0000000077c01407 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryKey 0000000077c01410 5 bytes JMP 000000017574f800
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryKey + 7 0000000077c01417 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryValueKey 0000000077c01420 5 bytes JMP 000000017574eac0
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryValueKey + 7 0000000077c01427 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory 0000000077c01430 5 bytes [49, C7, C2, 15, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateVirtualMemory + 7 0000000077c01437 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationProcess 0000000077c01440 5 bytes [49, C7, C2, 16, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationProcess + 7 0000000077c01447 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtWaitForMultipleObjects32 0000000077c01450 5 bytes [49, C7, C2, 17, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtWaitForMultipleObjects32 + 7 0000000077c01457 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtWriteFileGather 0000000077c01460 5 bytes [49, C7, C2, 18, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtWriteFileGather + 7 0000000077c01467 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess 0000000077c01470 1 byte JMP 0000000175753b00
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationProcess + 2 0000000077c01472 3 bytes {JMP 0xfffffffffdb52690}
.text ... * 2
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey 0000000077c01480 5 bytes JMP 000000017574e140
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateKey + 7 0000000077c01487 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory 0000000077c01490 5 bytes [49, C7, C2, 1B, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtFreeVirtualMemory + 7 0000000077c01497 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtImpersonateClientOfPort 0000000077c014a0 5 bytes JMP 00000001757450a0
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtImpersonateClientOfPort + 7 0000000077c014a7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReleaseMutant 0000000077c014b0 5 bytes [49, C7, C2, 1D, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReleaseMutant + 7 0000000077c014b7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationToken 0000000077c014c0 5 bytes [49, C7, C2, 1E, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationToken + 7 0000000077c014c7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtRequestWaitReplyPort 0000000077c014d0 5 bytes JMP 0000000175745740
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtRequestWaitReplyPort + 7 0000000077c014d7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryVirtualMemory 0000000077c014e0 5 bytes JMP 00000001757525d0
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryVirtualMemory + 7 0000000077c014e7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 0000000077c014f0 5 bytes [49, C7, C2, 21, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken + 7 0000000077c014f7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000077c01500 5 bytes [49, C7, C2, 22, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread + 7 0000000077c01507 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c01510 5 bytes JMP 000000017575e5b0
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess + 7 0000000077c01517 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile 0000000077c01520 5 bytes JMP 00000001757359c0
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationFile + 7 0000000077c01527 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAccessCheckAndAuditAlarm 0000000077c01540 5 bytes [49, C7, C2, 26, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAccessCheckAndAuditAlarm + 7 0000000077c01547 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077c01550 5 bytes [49, C7, C2, 27, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection + 7 0000000077c01557 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c01560 5 bytes [49, C7, C2, 28, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx + 7 0000000077c01567 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetEventBoostPriority 0000000077c01580 5 bytes [49, C7, C2, 2A, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetEventBoostPriority + 7 0000000077c01587 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReadFileScatter 0000000077c01590 5 bytes [49, C7, C2, 2B, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReadFileScatter + 7 0000000077c01597 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 0000000077c015a0 5 bytes [49, C7, C2, 2C, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx + 7 0000000077c015a7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessTokenEx 0000000077c015b0 5 bytes [49, C7, C2, 2D, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessTokenEx + 7 0000000077c015b7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryPerformanceCounter 0000000077c015c0 5 bytes [49, C7, C2, 2E, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryPerformanceCounter + 7 0000000077c015c7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtEnumerateKey 0000000077c015d0 5 bytes JMP 000000017574e5f0
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtEnumerateKey + 7 0000000077c015d7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077c015e0 5 bytes JMP 0000000175735cc0
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile + 7 0000000077c015e7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtDelayExecution 0000000077c015f0 5 bytes [49, C7, C2, 31, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtDelayExecution + 7 0000000077c015f7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryDirectoryFile 0000000077c01600 5 bytes JMP 000000017572fee0
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryDirectoryFile + 7 0000000077c01607 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQuerySystemInformation 0000000077c01610 5 bytes JMP 0000000175761130
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQuerySystemInformation + 7 0000000077c01617 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c01620 5 bytes JMP 0000000175748650
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection + 7 0000000077c01627 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryTimer 0000000077c01630 5 bytes [49, C7, C2, 35, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryTimer + 7 0000000077c01637 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtFsControlFile 0000000077c01640 5 bytes JMP 0000000175732d20
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtFsControlFile + 7 0000000077c01647 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c01650 5 bytes [49, C7, C2, 37, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory + 7 0000000077c01657 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCloseObjectAuditAlarm 0000000077c01660 5 bytes [49, C7, C2, 38, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCloseObjectAuditAlarm + 7 0000000077c01667 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c01670 5 bytes JMP 000000017575e690
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 7 0000000077c01677 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 0000000077c01680 5 bytes JMP 0000000175731d60
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile + 7 0000000077c01687 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtClearEvent 0000000077c01690 5 bytes [49, C7, C2, 3B, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtClearEvent + 7 0000000077c01697 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReadVirtualMemory 0000000077c016a0 5 bytes [49, C7, C2, 3C, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReadVirtualMemory + 7 0000000077c016a7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c016b0 5 bytes JMP 00000001757479e0
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent + 7 0000000077c016b7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken 0000000077c016c0 5 bytes JMP 000000017575dd70
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustPrivilegesToken + 7 0000000077c016c7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateToken 0000000077c016d0 5 bytes [49, C7, C2, 3F, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateToken + 7 0000000077c016d7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryDefaultUILanguage 0000000077c016f0 5 bytes [49, C7, C2, 41, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryDefaultUILanguage + 7 0000000077c016f7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000077c01700 5 bytes [49, C7, C2, 42, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread + 7 0000000077c01707 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtYieldExecution 0000000077c01710 5 bytes [49, C7, C2, 43, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtYieldExecution + 7 0000000077c01717 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAddAtom 0000000077c01720 5 bytes [49, C7, C2, 44, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAddAtom + 7 0000000077c01727 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c01730 5 bytes JMP 0000000175747790
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent + 7 0000000077c01737 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryVolumeInformationFile 0000000077c01740 5 bytes JMP 00000001757331f0
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryVolumeInformationFile + 7 0000000077c01747 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c01750 5 bytes JMP 0000000175748350
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection + 7 0000000077c01757 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtFlushBuffersFile 0000000077c01760 5 bytes [49, C7, C2, 48, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtFlushBuffersFile + 7 0000000077c01767 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtApphelpCacheControl 0000000077c01770 5 bytes [49, C7, C2, 49, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtApphelpCacheControl + 7 0000000077c01777 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 0000000077c01780 5 bytes [49, C7, C2, 4A, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx + 7 0000000077c01787 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c01790 5 bytes [49, C7, C2, 4B, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread + 7 0000000077c01797 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtIsProcessInJob 0000000077c017a0 5 bytes [49, C7, C2, 4C, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtIsProcessInJob + 7 0000000077c017a7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory 0000000077c017b0 5 bytes [49, C7, C2, 4D, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtProtectVirtualMemory + 7 0000000077c017b7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQuerySection 0000000077c017c0 5 bytes [49, C7, C2, 4E, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQuerySection + 7 0000000077c017c7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077c017d0 5 bytes [49, C7, C2, 4F, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread + 7 0000000077c017d7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReadRequestData 0000000077c017f0 5 bytes [49, C7, C2, 51, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtReadRequestData + 7 0000000077c017f7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077c01800 5 bytes JMP 0000000175733c40
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 7 0000000077c01807 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryEvent 0000000077c01810 5 bytes [49, C7, C2, 53, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryEvent + 7 0000000077c01817 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtWriteRequestData 0000000077c01820 5 bytes [49, C7, C2, 54, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtWriteRequestData + 7 0000000077c01827 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenDirectoryObject 0000000077c01830 5 bytes [49, C7, C2, 55, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenDirectoryObject + 7 0000000077c01837 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAccessCheckByTypeAndAuditAlarm 0000000077c01840 5 bytes [49, C7, C2, 56, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAccessCheckByTypeAndAuditAlarm + 7 0000000077c01847 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtWaitForMultipleObjects 0000000077c01860 5 bytes [49, C7, C2, 58, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtWaitForMultipleObjects + 7 0000000077c01867 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationObject 0000000077c01870 5 bytes [49, C7, C2, 59, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationObject + 7 0000000077c01877 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCancelIoFile 0000000077c01880 5 bytes [49, C7, C2, 5A, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCancelIoFile + 7 0000000077c01887 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtTraceEvent 0000000077c01890 5 bytes JMP 0000000175760e10
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtTraceEvent + 7 0000000077c01897 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtPowerInformation 0000000077c018a0 5 bytes [49, C7, C2, 5C, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtPowerInformation + 7 0000000077c018a7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey 0000000077c018b0 5 bytes JMP 000000017574cd50
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetValueKey + 7 0000000077c018b7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCancelTimer 0000000077c018c0 5 bytes [49, C7, C2, 5E, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtCancelTimer + 7 0000000077c018c7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetTimer 0000000077c018d0 5 bytes [49, C7, C2, 5F, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtSetTimer + 7 0000000077c018d7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAcceptConnectPort 0000000077c018e0 5 bytes [49, C7, C2, 60, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAcceptConnectPort + 7 0000000077c018e7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAccessCheck 0000000077c018f0 5 bytes [49, C7, C2, 61, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAccessCheck + 7 0000000077c018f7 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAccessCheckByType 0000000077c01900 5 bytes [49, C7, C2, 62, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAccessCheckByType + 7 0000000077c01907 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAccessCheckByTypeResultList 0000000077c01910 5 bytes [49, C7, C2, 63, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAccessCheckByTypeResultList + 7 0000000077c01917 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAccessCheckByTypeResultListAndAuditAlarm 0000000077c01920 5 bytes [49, C7, C2, 64, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAccessCheckByTypeResultListAndAuditAlarm + 7 0000000077c01927 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAccessCheckByTypeResultListAndAuditAlarmByHandle 0000000077c01930 5 bytes [49, C7, C2, 65, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAccessCheckByTypeResultListAndAuditAlarmByHandle + 7 0000000077c01937 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c01940 5 bytes [49, C7, C2, 66, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry + 7 0000000077c01947 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAddDriverEntry 0000000077c01950 5 bytes [49, C7, C2, 67, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAddDriverEntry + 7 0000000077c01957 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustGroupsToken 0000000077c01960 5 bytes [49, C7, C2, 68, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAdjustGroupsToken + 7 0000000077c01967 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAlertResumeThread 0000000077c01970 5 bytes [49, C7, C2, 69, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAlertResumeThread + 7 0000000077c01977 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAlertThread 0000000077c01980 5 bytes [49, C7, C2, 6A, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAlertThread + 7 0000000077c01987 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateLocallyUniqueId 0000000077c01990 5 bytes [49, C7, C2, 6B, 00]
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateLocallyUniqueId + 7 0000000077c01997 5 bytes JMP 0000000077d60060
.text C:\Program Files\Sandboxie\SandboxieRpcSs.exe[204] C:\Windows\SYSTEM32\ntdll.dll!NtAllocateReserveObject 0000000077c019a0 5 bytes [49, C7, C2, 6C, 00] Zitat:
Zitat von schrauber
(Beitrag 1238198)
Hi,
mit Internetkabel meinst Du die Verbindung von Router zu Inet, nicht zum Rechner oder? Schonmal deinen Citrix Client abgeschossen oder Avira udn geschaut ob es dann weg ist? | Ja, Verbindung vom Router zum Internet. Laptop ist ja mit WLAN zum Router verbunden.
Citrix Client ist eigentlich nie aktiviert außer wenn ich diese explizit starte, was sehr selten ist. Avira habe ich noch nicht probiert. Probiere mal es ganz auszumachen und gucke dann.
PS: Muss ich den GMER hier noch weiter aufteilen und posten? |