franzkans1 | 18.04.2014 16:26 | Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-04-17 22:56:54
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Intel___ rev.1.0. 596,18GB
Running: Gmer-19357.exe; Driver: C:\Users\GREGOR~1\AppData\Local\Temp\kgnirfod.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80003805000 45 bytes [00, 00, 15, 02, 46, 69, 6C, ...]
INITKDBG C:\windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff8000380502f 18 bytes [00, 00, 00, 00, 00, 00, 00, ...]
---- User code sections - GMER 2.1 ----
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 1 00000000774792d1 5 bytes [B8, 39, 69, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 7 00000000774792d7 5 bytes [00, 00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtWriteFile 0000000077491330 6 bytes [48, B8, B9, F1, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtWriteFile + 8 0000000077491338 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtClose 00000000774913a0 6 bytes [48, B8, B9, D5, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtClose + 8 00000000774913a8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationProcess 0000000077491470 6 bytes [48, B8, 79, C2, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationProcess + 8 0000000077491478 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077491510 6 bytes [48, B8, F9, 32, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtOpenProcess + 8 0000000077491518 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077491530 6 bytes [48, B8, 39, 1C, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 8 0000000077491538 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077491550 6 bytes [48, B8, F9, 1D, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection + 8 0000000077491558 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077491570 6 bytes [48, B8, B9, C0, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000077491578 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077491620 6 bytes [48, B8, 39, EE, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtOpenSection + 8 0000000077491628 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077491650 6 bytes [48, B8, 79, 2F, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory + 8 0000000077491658 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077491670 6 bytes [48, B8, 79, 36, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 8 0000000077491678 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000077491700 6 bytes [48, B8, B9, 34, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread + 8 0000000077491708 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077491750 6 bytes [48, B8, 79, F3, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtCreateSection + 8 0000000077491758 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 0000000077491780 6 bytes [48, B8, 39, 2A, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcessEx + 8 0000000077491788 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077491790 6 bytes [48, B8, B9, 26, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtCreateThread + 8 0000000077491798 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077491800 6 bytes [48, B8, F9, EF, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtCreateFile + 8 0000000077491808 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000774918b0 6 bytes [48, B8, F9, F6, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtSetValueKey + 8 00000000774918b8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077491c80 6 bytes [48, B8, 79, EC, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtCreateMutant + 8 0000000077491c88 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcess 0000000077491cd0 6 bytes [48, B8, 79, 28, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcess + 8 0000000077491cd8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077491d30 6 bytes [48, B8, F9, 24, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx + 8 0000000077491d38 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtLoadDriver 00000000774920a0 6 bytes [48, B8, 79, D7, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtLoadDriver + 8 00000000774920a8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtRaiseHardError 00000000774925e0 6 bytes [48, B8, 79, 83, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtRaiseHardError + 8 00000000774925e8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774927e0 6 bytes [48, B8, 39, 31, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread + 8 00000000774927e8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 00000000774929a0 6 bytes [48, B8, 39, D9, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtSetSystemInformation + 8 00000000774929a8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077492a80 6 bytes [48, B8, 79, 3D, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtSuspendProcess + 8 0000000077492a88 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077492a90 6 bytes [48, B8, B9, 3B, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtSuspendThread + 8 0000000077492a98 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077492aa0 6 bytes [48, B8, 39, F5, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtSystemDebugControl + 8 0000000077492aa8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077492b80 6 bytes [48, B8, 39, E7, 06, 6C]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!NtVdmControl + 8 0000000077492b88 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\SYSTEM32\ntdll.dll!RtlReportException + 1 0000000077503201 11 bytes [B8, 39, 85, 06, 6C, 00, 00, ...]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\system32\KERNELBASE.dll!CloseHandle + 1 000007fefd421861 11 bytes [B8, 79, 52, 06, 6C, 00, 00, ...]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\system32\KERNELBASE.dll!FreeLibrary + 1 000007fefd422db1 11 bytes [B8, B9, C7, 06, 6C, 00, 00, ...]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\system32\KERNELBASE.dll!GetProcAddress + 1 000007fefd423461 11 bytes [B8, 79, C9, 06, 6C, 00, 00, ...]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd428ef0 12 bytes [48, B8, F9, C5, 06, 6C, 00, ...]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\system32\KERNELBASE.dll!CreateMutexW 000007fefd4294c0 12 bytes [48, B8, B9, 50, 06, 6C, 00, ...]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 000007fefd42bfd1 11 bytes [B8, 39, C4, 06, 6C, 00, 00, ...]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\system32\KERNELBASE.dll!OpenMutexW + 1 000007fefd432af1 11 bytes [B8, F9, 4E, 06, 6C, 00, 00, ...]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fefd454350 12 bytes [48, B8, B9, 42, 06, 6C, 00, ...]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\system32\KERNELBASE.dll!CreateRemoteThread + 1 000007fefd462871 8 bytes [B8, 39, 23, 06, 6C, 00, 00, ...]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\system32\KERNELBASE.dll!CreateRemoteThread + 10 000007fefd46287a 2 bytes [50, C3]
.text C:\windows\system32\SearchIndexer.exe[3932] C:\windows\system32\KERNELBASE.dll!CreateThread + 1 000007fefd4628b1 11 bytes [B8, F9, 40, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\KERNELBASE.dll!CloseHandle + 1 000007fefd421861 11 bytes [B8, 79, 52, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\KERNELBASE.dll!FreeLibrary + 1 000007fefd422db1 11 bytes [B8, B9, C7, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\KERNELBASE.dll!GetProcAddress + 1 000007fefd423461 11 bytes [B8, 79, C9, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd428ef0 12 bytes [48, B8, F9, C5, 06, 6C, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\KERNELBASE.dll!CreateMutexW 000007fefd4294c0 12 bytes [48, B8, B9, 50, 06, 6C, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 000007fefd42bfd1 11 bytes [B8, 39, C4, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\KERNELBASE.dll!OpenMutexW + 1 000007fefd432af1 11 bytes [B8, F9, 4E, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fefd454350 12 bytes [48, B8, B9, 42, 06, 6C, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\KERNELBASE.dll!CreateRemoteThread + 1 000007fefd462871 8 bytes [B8, 39, 23, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\KERNELBASE.dll!CreateRemoteThread + 10 000007fefd46287a 2 bytes [50, C3]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\KERNELBASE.dll!CreateThread + 1 000007fefd4628b1 11 bytes [B8, F9, 40, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\SYSTEM32\sechost.dll!ControlService + 1 000007fefe95642d 11 bytes [B8, 39, 5B, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\SYSTEM32\sechost.dll!OpenServiceW 000007fefe956484 12 bytes [48, B8, F9, 55, 06, 6C, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 000007fefe956519 11 bytes [B8, 39, 62, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\SYSTEM32\sechost.dll!OpenServiceA 000007fefe956c34 12 bytes [48, B8, 39, 54, 06, 6C, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\SYSTEM32\sechost.dll!DeleteService + 1 000007fefe957ab5 11 bytes [B8, F9, 5C, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 000007fefe958b01 11 bytes [B8, B9, 57, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 000007fefe958c39 11 bytes [B8, 79, 59, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\WS2_32.dll!WSASend + 1 000007fefe9013b1 11 bytes [B8, F9, BE, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\WS2_32.dll!closesocket 000007fefe9018e0 12 bytes [48, B8, 39, BD, 06, 6C, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\WS2_32.dll!WSASocketW + 1 000007fefe901bd1 11 bytes [B8, 79, BB, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\WS2_32.dll!WSARecv + 1 000007fefe902201 11 bytes [B8, F9, E1, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\WS2_32.dll!GetAddrInfoW 000007fefe9023c0 12 bytes [48, B8, 79, A6, 06, 6C, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\WS2_32.dll!connect 000007fefe9045c0 12 bytes [48, B8, 79, 67, 06, 6C, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\WS2_32.dll!send + 1 000007fefe908001 11 bytes [B8, B9, B9, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\WS2_32.dll!gethostbyname 000007fefe908df0 7 bytes [48, B8, 39, A8, 06, 6C, 00]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\WS2_32.dll!gethostbyname + 9 000007fefe908df9 3 bytes [00, 50, C3]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\WS2_32.dll!socket + 1 000007fefe90de91 11 bytes [B8, F9, DA, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\WS2_32.dll!recv + 1 000007fefe90df41 11 bytes [B8, 39, E0, 06, 6C, 00, 00, ...]
.text C:\windows\system32\wbem\wmiprvse.exe[4576] C:\windows\system32\WS2_32.dll!WSAConnect + 1 000007fefe92e0f1 11 bytes [B8, 79, DE, 06, 6C, 00, 00, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtWriteFile 000000007763f928 5 bytes JMP 0000000174776811
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtClose 000000007763f9e0 5 bytes JMP 00000001747760c1
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtSetInformationProcess 000000007763fb28 5 bytes JMP 0000000174775b21
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtOpenProcess 000000007763fc20 5 bytes JMP 0000000174773061
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007763fc50 5 bytes JMP 00000001747715f1
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection 000000007763fc80 5 bytes JMP 0000000174771681
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtTerminateProcess 000000007763fcb0 5 bytes JMP 0000000174775a91
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtOpenSection 000000007763fdc8 5 bytes JMP 0000000174776781
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007763fe14 5 bytes JMP 0000000174772f41
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtDuplicateObject 000000007763fe44 5 bytes JMP 0000000174773181
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtQueueApcThread 000000007763ff24 5 bytes JMP 00000001747730f1
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtCreateSection 000000007763ffa4 5 bytes JMP 00000001747768a1
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtCreateProcessEx 000000007763ffec 5 bytes JMP 0000000174772d91
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtCreateThread 0000000077640004 5 bytes JMP 0000000174772c71
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtCreateFile 00000000776400b4 5 bytes JMP 0000000174771e61
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtSetValueKey 00000000776401c4 5 bytes JMP 0000000174772251
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtCreateMutant 000000007764079c 5 bytes JMP 00000001747766f1
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtCreateProcess 0000000077640814 5 bytes JMP 0000000174772d01
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtCreateThreadEx 00000000776408a4 5 bytes JMP 0000000174772be1
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtLoadDriver 0000000077640df4 5 bytes JMP 0000000174776151
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtRaiseHardError 0000000077641604 5 bytes JMP 0000000174774801
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077641920 5 bytes JMP 0000000174772fd1
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtSetSystemInformation 0000000077641be4 5 bytes JMP 00000001747761e1
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtSuspendProcess 0000000077641d54 5 bytes JMP 00000001747732a1
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtSuspendThread 0000000077641d70 5 bytes JMP 0000000174773211
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtSystemDebugControl 0000000077641d8c 5 bytes JMP 0000000174776931
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!NtVdmControl 0000000077641ee8 5 bytes JMP 0000000174776541
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!RtlQueryPerformanceCounter 00000000776588c4 5 bytes JMP 0000000174771a71
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!RtlCreateProcessParametersEx 0000000077680d3b 5 bytes JMP 0000000174771f81
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!RtlReportException 00000000776c860f 5 bytes JMP 0000000174774891
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\SysWOW64\ntdll.dll!RtlCreateProcessParameters 00000000776ce8ab 5 bytes JMP 0000000174771ef1
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\syswow64\KERNEL32.dll!GetStartupInfoA 0000000076e20e00 5 bytes JMP 0000000174771d41
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\syswow64\KERNEL32.dll!CreateProcessA 0000000076e21072 5 bytes JMP 0000000174772911
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\syswow64\KERNEL32.dll!LoadLibraryA 0000000076e2499f 5 bytes JMP 0000000174772521
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\syswow64\KERNEL32.dll!CreateProcessInternalW 0000000076e33bbb 5 bytes JMP 0000000174772eb1
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\syswow64\KERNEL32.dll!CreateToolhelp32Snapshot 0000000076e47327 5 bytes JMP 0000000174772641
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\syswow64\KERNEL32.dll!Process32NextW 0000000076e488da 5 bytes JMP 0000000174776031
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\syswow64\KERNEL32.dll!WinExec 0000000076ea2ff1 5 bytes JMP 00000001747727f1
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\syswow64\KERNEL32.dll!ReadConsoleInputA 0000000076ec748b 5 bytes JMP 0000000174774411
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\syswow64\KERNEL32.dll!ReadConsoleInputW 0000000076ec74ae 5 bytes JMP 0000000174774531
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\syswow64\KERNEL32.dll!ReadConsoleA 0000000076ec7859 5 bytes JMP 0000000174774651
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[4700] C:\windows\syswow64\KERNEL32.dll!ReadConsoleW 0000000076ec78d2 5 bytes JMP 0000000174774771
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtWriteFile 000000007763f928 5 bytes JMP 0000000174776811
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtClose 000000007763f9e0 5 bytes JMP 00000001747760c1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtSetInformationProcess 000000007763fb28 5 bytes JMP 0000000174775b21
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtOpenProcess 000000007763fc20 5 bytes JMP 0000000174773061
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtMapViewOfSection 000000007763fc50 5 bytes JMP 00000001747715f1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection 000000007763fc80 5 bytes JMP 0000000174771681
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtTerminateProcess 000000007763fcb0 5 bytes JMP 0000000174775a91
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtOpenSection 000000007763fdc8 5 bytes JMP 0000000174776781
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 000000007763fe14 5 bytes JMP 0000000174772f41
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtDuplicateObject 000000007763fe44 5 bytes JMP 0000000174773181
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtQueueApcThread 000000007763ff24 5 bytes JMP 00000001747730f1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtCreateSection 000000007763ffa4 5 bytes JMP 00000001747768a1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtCreateProcessEx 000000007763ffec 5 bytes JMP 0000000174772d91
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtCreateThread 0000000077640004 5 bytes JMP 0000000174772c71
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtCreateFile 00000000776400b4 5 bytes JMP 0000000174771e61
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtSetValueKey 00000000776401c4 5 bytes JMP 0000000174772251
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtCreateMutant 000000007764079c 5 bytes JMP 00000001747766f1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtCreateProcess 0000000077640814 5 bytes JMP 0000000174772d01
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtCreateThreadEx 00000000776408a4 5 bytes JMP 0000000174772be1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtLoadDriver 0000000077640df4 5 bytes JMP 0000000174776151
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtRaiseHardError 0000000077641604 5 bytes JMP 0000000174774801
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077641920 5 bytes JMP 0000000174772fd1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtSetSystemInformation 0000000077641be4 5 bytes JMP 00000001747761e1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtSuspendProcess 0000000077641d54 5 bytes JMP 00000001747732a1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtSuspendThread 0000000077641d70 5 bytes JMP 0000000174773211
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtSystemDebugControl 0000000077641d8c 5 bytes JMP 0000000174776931
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!NtVdmControl 0000000077641ee8 5 bytes JMP 0000000174776541
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!RtlQueryPerformanceCounter 00000000776588c4 5 bytes JMP 0000000174771a71
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!RtlCreateProcessParametersEx 0000000077680d3b 5 bytes JMP 0000000174771f81
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!RtlReportException 00000000776c860f 5 bytes JMP 0000000174774891
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\SysWOW64\ntdll.dll!RtlCreateProcessParameters 00000000776ce8ab 5 bytes JMP 0000000174771ef1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!GetSystemTimeAsFileTime 0000000075f68f7d 5 bytes JMP 00000001747719e1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!CloseHandle 0000000075f6c428 5 bytes JMP 0000000174773961
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!WriteProcessMemory 0000000075f6ec98 5 bytes JMP 0000000174773451
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!ExitProcess 0000000075f6f1f8 5 bytes JMP 00000001747722e1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!GetStartupInfoW 0000000075f6fa7b 5 bytes JMP 0000000174771dd1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!CreateMutexW 0000000075f7134a 5 bytes JMP 00000001747738d1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!OpenMutexW 0000000075f71371 5 bytes JMP 0000000174773841
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075f71d1b 5 bytes JMP 0000000174771951
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!GetProcAddress 0000000075f71e07 5 bytes JMP 0000000174772401
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075f72aa4 5 bytes JMP 0000000174775c41
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!LoadLibraryExA 0000000075f72ccc 5 bytes JMP 0000000174775bb1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075f72d0a 5 bytes JMP 0000000174775cd1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!GetModuleHandleA 0000000075f72e6d 5 bytes JMP 00000001747718c1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!SleepEx 0000000075f73b63 5 bytes JMP 00000001747721c1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!Sleep 0000000075f74489 5 bytes JMP 0000000174772371
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!CreateThread 0000000075f745fb 5 bytes JMP 00000001747733c1
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!CreateRemoteThread 0000000075f74624 5 bytes JMP 0000000174772b51
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[344] C:\windows\syswow64\KERNELBASE.dll!CreateFileA 0000000075f7c72c 5 bytes JMP 00000001747726d1
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[5344] C:\windows\system32\WS2_32.dll!WSASend + 1 000007fefe9013b1 11 bytes [B8, F9, BE, 06, 6C, 00, 00, ...]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[5344] C:\windows\system32\WS2_32.dll!closesocket 000007fefe9018e0 12 bytes [48, B8, 39, BD, 06, 6C, 00, ...]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[5344] C:\windows\system32\WS2_32.dll!WSASocketW + 1 000007fefe901bd1 11 bytes [B8, 79, BB, 06, 6C, 00, 00, ...]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[5344] C:\windows\system32\WS2_32.dll!WSARecv + 1 000007fefe902201 11 bytes [B8, F9, E1, 06, 6C, 00, 00, ...]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[5344] C:\windows\system32\WS2_32.dll!GetAddrInfoW 000007fefe9023c0 12 bytes [48, B8, 79, A6, 06, 6C, 00, ...]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[5344] C:\windows\system32\WS2_32.dll!connect 000007fefe9045c0 12 bytes [48, B8, 79, 67, 06, 6C, 00, ...]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[5344] C:\windows\system32\WS2_32.dll!send + 1 000007fefe908001 11 bytes [B8, B9, B9, 06, 6C, 00, 00, ...]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[5344] C:\windows\system32\WS2_32.dll!gethostbyname 000007fefe908df0 7 bytes [48, B8, 39, A8, 06, 6C, 00]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[5344] C:\windows\system32\WS2_32.dll!gethostbyname + 9 000007fefe908df9 3 bytes [00, 50, C3]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[5344] C:\windows\system32\WS2_32.dll!socket + 1 000007fefe90de91 11 bytes [B8, F9, DA, 06, 6C, 00, 00, ...]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[5344] C:\windows\system32\WS2_32.dll!recv + 1 000007fefe90df41 11 bytes [B8, 39, E0, 06, 6C, 00, 00, ...]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[5344] C:\windows\system32\WS2_32.dll!WSAConnect + 1 000007fefe92e0f1 11 bytes [B8, 79, DE, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 1 00000000774792d1 5 bytes [B8, 39, 69, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 7 00000000774792d7 5 bytes [00, 00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtWriteFile 0000000077491330 6 bytes [48, B8, B9, F1, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtWriteFile + 8 0000000077491338 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtClose 00000000774913a0 6 bytes [48, B8, B9, D5, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtClose + 8 00000000774913a8 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationProcess 0000000077491470 6 bytes [48, B8, 79, C2, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationProcess + 8 0000000077491478 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077491510 6 bytes [48, B8, F9, 32, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtOpenProcess + 8 0000000077491518 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077491530 6 bytes [48, B8, 39, 1C, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 8 0000000077491538 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077491550 6 bytes [48, B8, F9, 1D, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection + 8 0000000077491558 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077491570 6 bytes [48, B8, B9, C0, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000077491578 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077491620 6 bytes [48, B8, 39, EE, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtOpenSection + 8 0000000077491628 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077491650 6 bytes [48, B8, 79, 2F, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory + 8 0000000077491658 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077491670 6 bytes [48, B8, 79, 36, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 8 0000000077491678 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000077491700 6 bytes [48, B8, B9, 34, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread + 8 0000000077491708 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077491750 6 bytes [48, B8, 79, F3, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtCreateSection + 8 0000000077491758 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 0000000077491780 6 bytes [48, B8, 39, 2A, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcessEx + 8 0000000077491788 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077491790 6 bytes [48, B8, B9, 26, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtCreateThread + 8 0000000077491798 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077491800 6 bytes [48, B8, F9, EF, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtCreateFile + 8 0000000077491808 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000774918b0 6 bytes [48, B8, F9, F6, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtSetValueKey + 8 00000000774918b8 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077491c80 6 bytes [48, B8, 79, EC, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtCreateMutant + 8 0000000077491c88 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcess 0000000077491cd0 6 bytes [48, B8, 79, 28, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcess + 8 0000000077491cd8 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077491d30 6 bytes [48, B8, F9, 24, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx + 8 0000000077491d38 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtLoadDriver 00000000774920a0 6 bytes [48, B8, 79, D7, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtLoadDriver + 8 00000000774920a8 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtRaiseHardError 00000000774925e0 6 bytes [48, B8, 79, 83, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtRaiseHardError + 8 00000000774925e8 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774927e0 6 bytes [48, B8, 39, 31, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread + 8 00000000774927e8 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 00000000774929a0 6 bytes [48, B8, 39, D9, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtSetSystemInformation + 8 00000000774929a8 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077492a80 6 bytes [48, B8, 79, 3D, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtSuspendProcess + 8 0000000077492a88 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077492a90 6 bytes [48, B8, B9, 3B, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtSuspendThread + 8 0000000077492a98 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077492aa0 6 bytes [48, B8, 39, F5, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtSystemDebugControl + 8 0000000077492aa8 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077492b80 6 bytes [48, B8, 39, E7, 06, 6C]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!NtVdmControl + 8 0000000077492b88 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\ntdll.dll!RtlReportException + 1 0000000077503201 11 bytes [B8, 39, 85, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\kernel32.dll!Process32NextW + 1 0000000077321b21 11 bytes [B8, F9, D3, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\kernel32.dll!CreateToolhelp32Snapshot 0000000077321c10 12 bytes [48, B8, F9, 39, 06, 6C, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\kernel32.dll!CreateProcessInternalW 000000007733db80 12 bytes [48, B8, B9, 2D, 06, 6C, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\kernel32.dll!GetStartupInfoA + 1 0000000077340931 11 bytes [B8, 79, E5, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\kernel32.dll!ReadConsoleInputW + 1 00000000773752f1 11 bytes [B8, B9, 7A, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\kernel32.dll!ReadConsoleInputA + 1 0000000077375311 11 bytes [B8, 39, 77, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\kernel32.dll!ReadConsoleW 000000007738a5e0 12 bytes [48, B8, B9, 81, 06, 6C, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\kernel32.dll!ReadConsoleA 000000007738a6f0 12 bytes [48, B8, 39, 7E, 06, 6C, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\KERNELBASE.dll!CloseHandle + 1 000007fefd421861 11 bytes [B8, 79, 52, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\KERNELBASE.dll!FreeLibrary + 1 000007fefd422db1 11 bytes [B8, B9, C7, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\KERNELBASE.dll!GetProcAddress + 1 000007fefd423461 11 bytes [B8, 79, C9, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd428ef0 12 bytes [48, B8, F9, C5, 06, 6C, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\KERNELBASE.dll!CreateMutexW 000007fefd4294c0 12 bytes [48, B8, B9, 50, 06, 6C, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 000007fefd42bfd1 11 bytes [B8, 39, C4, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\KERNELBASE.dll!OpenMutexW + 1 000007fefd432af1 11 bytes [B8, F9, 4E, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fefd454350 12 bytes [48, B8, B9, 42, 06, 6C, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\KERNELBASE.dll!CreateRemoteThread + 1 000007fefd462871 8 bytes [B8, 39, 23, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\KERNELBASE.dll!CreateRemoteThread + 10 000007fefd46287a 2 bytes [50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\system32\KERNELBASE.dll!CreateThread + 1 000007fefd4628b1 11 bytes [B8, F9, 40, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\sechost.dll!ControlService + 1 000007fefe95642d 11 bytes [B8, 39, 5B, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\sechost.dll!OpenServiceW 000007fefe956484 12 bytes [48, B8, F9, 55, 06, 6C, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 000007fefe956519 11 bytes [B8, 39, 62, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\sechost.dll!OpenServiceA 000007fefe956c34 12 bytes [48, B8, 39, 54, 06, 6C, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\sechost.dll!DeleteService + 1 000007fefe957ab5 11 bytes [B8, F9, 5C, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 000007fefe958b01 11 bytes [B8, B9, 57, 06, 6C, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[5604] C:\windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 000007fefe958c39 11 bytes [B8, 79, 59, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 1 00000000774792d1 5 bytes [B8, 39, 69, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 7 00000000774792d7 5 bytes [00, 00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtWriteFile 0000000077491330 6 bytes [48, B8, B9, F1, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtWriteFile + 8 0000000077491338 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtClose 00000000774913a0 6 bytes [48, B8, B9, D5, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtClose + 8 00000000774913a8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationProcess 0000000077491470 6 bytes [48, B8, 79, C2, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationProcess + 8 0000000077491478 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077491510 6 bytes [48, B8, F9, 32, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtOpenProcess + 8 0000000077491518 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077491530 6 bytes [48, B8, 39, 1C, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 8 0000000077491538 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077491550 6 bytes [48, B8, F9, 1D, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection + 8 0000000077491558 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077491570 6 bytes [48, B8, B9, C0, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000077491578 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077491620 6 bytes [48, B8, 39, EE, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtOpenSection + 8 0000000077491628 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077491650 6 bytes [48, B8, 79, 2F, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory + 8 0000000077491658 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077491670 6 bytes [48, B8, 79, 36, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 8 0000000077491678 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000077491700 6 bytes [48, B8, B9, 34, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread + 8 0000000077491708 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077491750 6 bytes [48, B8, 79, F3, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateSection + 8 0000000077491758 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 0000000077491780 6 bytes [48, B8, 39, 2A, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcessEx + 8 0000000077491788 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077491790 6 bytes [48, B8, B9, 26, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateThread + 8 0000000077491798 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077491800 6 bytes [48, B8, F9, EF, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateFile + 8 0000000077491808 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000774918b0 6 bytes [48, B8, F9, F6, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSetValueKey + 8 00000000774918b8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077491c80 6 bytes [48, B8, 79, EC, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateMutant + 8 0000000077491c88 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcess 0000000077491cd0 6 bytes [48, B8, 79, 28, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcess + 8 0000000077491cd8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077491d30 6 bytes [48, B8, F9, 24, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx + 8 0000000077491d38 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtLoadDriver 00000000774920a0 6 bytes [48, B8, 79, D7, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtLoadDriver + 8 00000000774920a8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtRaiseHardError 00000000774925e0 6 bytes [48, B8, 79, 83, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtRaiseHardError + 8 00000000774925e8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774927e0 6 bytes [48, B8, 39, 31, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread + 8 00000000774927e8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 00000000774929a0 6 bytes [48, B8, 39, D9, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSetSystemInformation + 8 00000000774929a8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077492a80 6 bytes [48, B8, 79, 3D, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSuspendProcess + 8 0000000077492a88 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077492a90 6 bytes [48, B8, B9, 3B, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSuspendThread + 8 0000000077492a98 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077492aa0 6 bytes [48, B8, 39, F5, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtSystemDebugControl + 8 0000000077492aa8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077492b80 6 bytes [48, B8, 39, E7, 06, 6C]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!NtVdmControl + 8 0000000077492b88 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\ntdll.dll!RtlReportException + 1 0000000077503201 11 bytes [B8, 39, 85, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\kernel32.dll!Process32NextW + 1 0000000077321b21 11 bytes [B8, F9, D3, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\kernel32.dll!CreateToolhelp32Snapshot 0000000077321c10 12 bytes [48, B8, F9, 39, 06, 6C, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\kernel32.dll!CreateProcessInternalW 000000007733db80 12 bytes [48, B8, B9, 2D, 06, 6C, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\kernel32.dll!GetStartupInfoA + 1 0000000077340931 11 bytes [B8, 79, E5, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\kernel32.dll!ReadConsoleInputW + 1 00000000773752f1 11 bytes [B8, B9, 7A, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\kernel32.dll!ReadConsoleInputA + 1 0000000077375311 11 bytes [B8, 39, 77, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\kernel32.dll!ReadConsoleW 000000007738a5e0 12 bytes [48, B8, B9, 81, 06, 6C, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\kernel32.dll!ReadConsoleA 000000007738a6f0 12 bytes [48, B8, 39, 7E, 06, 6C, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\KERNELBASE.dll!CloseHandle + 1 000007fefd421861 11 bytes [B8, 79, 52, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\KERNELBASE.dll!FreeLibrary + 1 000007fefd422db1 11 bytes [B8, B9, C7, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\KERNELBASE.dll!GetProcAddress + 1 000007fefd423461 11 bytes [B8, 79, C9, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd428ef0 12 bytes [48, B8, F9, C5, 06, 6C, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\KERNELBASE.dll!CreateMutexW 000007fefd4294c0 12 bytes [48, B8, B9, 50, 06, 6C, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 000007fefd42bfd1 11 bytes [B8, 39, C4, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\KERNELBASE.dll!OpenMutexW + 1 000007fefd432af1 11 bytes [B8, F9, 4E, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fefd454350 12 bytes [48, B8, B9, 42, 06, 6C, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\KERNELBASE.dll!CreateRemoteThread + 1 000007fefd462871 8 bytes [B8, 39, 23, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\KERNELBASE.dll!CreateRemoteThread + 10 000007fefd46287a 2 bytes [50, C3]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\system32\KERNELBASE.dll!CreateThread + 1 000007fefd4628b1 11 bytes [B8, F9, 40, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\sechost.dll!ControlService + 1 000007fefe95642d 11 bytes [B8, 39, 5B, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\sechost.dll!OpenServiceW 000007fefe956484 12 bytes [48, B8, F9, 55, 06, 6C, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 000007fefe956519 11 bytes [B8, 39, 62, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\sechost.dll!OpenServiceA 000007fefe956c34 12 bytes [48, B8, 39, 54, 06, 6C, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\sechost.dll!DeleteService + 1 000007fefe957ab5 11 bytes [B8, F9, 5C, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 000007fefe958b01 11 bytes [B8, B9, 57, 06, 6C, 00, 00, ...]
.text C:\windows\system32\nvvsvc.exe[5600] C:\windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 000007fefe958c39 11 bytes [B8, 79, 59, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 1 00000000774792d1 5 bytes [B8, 39, 69, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 7 00000000774792d7 5 bytes [00, 00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtWriteFile 0000000077491330 6 bytes [48, B8, B9, F1, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtWriteFile + 8 0000000077491338 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtClose 00000000774913a0 6 bytes [48, B8, B9, D5, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtClose + 8 00000000774913a8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationProcess 0000000077491470 6 bytes [48, B8, 79, C2, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationProcess + 8 0000000077491478 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077491510 6 bytes [48, B8, F9, 32, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtOpenProcess + 8 0000000077491518 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077491530 6 bytes [48, B8, 39, 1C, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 8 0000000077491538 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077491550 6 bytes [48, B8, F9, 1D, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection + 8 0000000077491558 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077491570 6 bytes [48, B8, B9, C0, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000077491578 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077491620 6 bytes [48, B8, 39, EE, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtOpenSection + 8 0000000077491628 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077491650 6 bytes [48, B8, 79, 2F, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory + 8 0000000077491658 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077491670 6 bytes [48, B8, 79, 36, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 8 0000000077491678 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000077491700 6 bytes [48, B8, B9, 34, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread + 8 0000000077491708 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077491750 6 bytes [48, B8, 79, F3, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtCreateSection + 8 0000000077491758 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 0000000077491780 6 bytes [48, B8, 39, 2A, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcessEx + 8 0000000077491788 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077491790 6 bytes [48, B8, B9, 26, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtCreateThread + 8 0000000077491798 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077491800 6 bytes [48, B8, F9, EF, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtCreateFile + 8 0000000077491808 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000774918b0 6 bytes [48, B8, F9, F6, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtSetValueKey + 8 00000000774918b8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077491c80 6 bytes [48, B8, 79, EC, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtCreateMutant + 8 0000000077491c88 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcess 0000000077491cd0 6 bytes [48, B8, 79, 28, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcess + 8 0000000077491cd8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077491d30 6 bytes [48, B8, F9, 24, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx + 8 0000000077491d38 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtLoadDriver 00000000774920a0 6 bytes [48, B8, 79, D7, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtLoadDriver + 8 00000000774920a8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtRaiseHardError 00000000774925e0 6 bytes [48, B8, 79, 83, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtRaiseHardError + 8 00000000774925e8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774927e0 6 bytes [48, B8, 39, 31, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread + 8 00000000774927e8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 00000000774929a0 6 bytes [48, B8, 39, D9, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtSetSystemInformation + 8 00000000774929a8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077492a80 6 bytes [48, B8, 79, 3D, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtSuspendProcess + 8 0000000077492a88 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077492a90 6 bytes [48, B8, B9, 3B, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtSuspendThread + 8 0000000077492a98 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077492aa0 6 bytes [48, B8, 39, F5, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtSystemDebugControl + 8 0000000077492aa8 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077492b80 6 bytes [48, B8, 39, E7, 06, 6C]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!NtVdmControl + 8 0000000077492b88 4 bytes [00, 00, 50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\ntdll.dll!RtlReportException + 1 0000000077503201 11 bytes [B8, 39, 85, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\kernel32.dll!Process32NextW + 1 0000000077321b21 11 bytes [B8, F9, D3, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\kernel32.dll!CreateToolhelp32Snapshot 0000000077321c10 12 bytes [48, B8, F9, 39, 06, 6C, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\kernel32.dll!CreateProcessInternalW 000000007733db80 12 bytes [48, B8, B9, 2D, 06, 6C, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\kernel32.dll!GetStartupInfoA + 1 0000000077340931 11 bytes [B8, 79, E5, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\kernel32.dll!ReadConsoleInputW + 1 00000000773752f1 11 bytes [B8, B9, 7A, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\kernel32.dll!ReadConsoleInputA + 1 0000000077375311 11 bytes [B8, 39, 77, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\kernel32.dll!ReadConsoleW 000000007738a5e0 12 bytes [48, B8, B9, 81, 06, 6C, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\kernel32.dll!ReadConsoleA 000000007738a6f0 12 bytes [48, B8, 39, 7E, 06, 6C, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\KERNELBASE.dll!CloseHandle + 1 000007fefd421861 11 bytes [B8, 79, 52, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\KERNELBASE.dll!FreeLibrary + 1 000007fefd422db1 11 bytes [B8, B9, C7, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\KERNELBASE.dll!GetProcAddress + 1 000007fefd423461 11 bytes [B8, 79, C9, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd428ef0 12 bytes [48, B8, F9, C5, 06, 6C, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\KERNELBASE.dll!CreateMutexW 000007fefd4294c0 12 bytes [48, B8, B9, 50, 06, 6C, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 000007fefd42bfd1 11 bytes [B8, 39, C4, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\KERNELBASE.dll!OpenMutexW + 1 000007fefd432af1 11 bytes [B8, F9, 4E, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fefd454350 12 bytes [48, B8, B9, 42, 06, 6C, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\KERNELBASE.dll!CreateRemoteThread + 1 000007fefd462871 8 bytes [B8, 39, 23, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\KERNELBASE.dll!CreateRemoteThread + 10 000007fefd46287a 2 bytes [50, C3]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\KERNELBASE.dll!CreateThread + 1 000007fefd4628b1 11 bytes [B8, F9, 40, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\sechost.dll!ControlService + 1 000007fefe95642d 11 bytes [B8, 39, 5B, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\sechost.dll!OpenServiceW 000007fefe956484 12 bytes [48, B8, F9, 55, 06, 6C, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 000007fefe956519 11 bytes [B8, 39, 62, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\sechost.dll!OpenServiceA 000007fefe956c34 12 bytes [48, B8, 39, 54, 06, 6C, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\sechost.dll!DeleteService + 1 000007fefe957ab5 11 bytes [B8, F9, 5C, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 000007fefe958b01 11 bytes [B8, B9, 57, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 000007fefe958c39 11 bytes [B8, 79, 59, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\ADVAPI32.dll!IsTextUnicode + 49 000007feff114ea1 11 bytes [B8, 79, FA, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\ADVAPI32.dll!CreateServiceW 000007feff1155c8 12 bytes [48, B8, B9, 6C, 06, 6C, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\ADVAPI32.dll!CreateServiceA 000007feff12b85c 12 bytes [48, B8, F9, 6A, 06, 6C, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\ADVAPI32.dll!ChangeServiceConfigW 000007feff12b9d0 12 bytes [48, B8, 79, 60, 06, 6C, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\ADVAPI32.dll!ChangeServiceConfigA 000007feff12ba3c 12 bytes [48, B8, B9, 5E, 06, 6C, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\Dxva2.dll!DXVA2CreateVideoService + 1 000007fef99e3b21 11 bytes [B8, 39, 9A, 06, 6C, 00, 00, ...]
.text C:\windows\system32\taskhost.exe[4600] C:\windows\system32\Dxva2.dll!DXVAHD_CreateDevice + 1 000007fef99efbd1 11 bytes [B8, F9, 94, 06, 6C, 00, 00, ...]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 1 00000000774792d1 5 bytes [B8, F9, 55, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!RtlCreateProcessParametersEx + 7 00000000774792d7 5 bytes [00, 00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationProcess 0000000077491470 6 bytes [48, B8, F9, 5C, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtSetInformationProcess + 8 0000000077491478 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077491510 6 bytes [48, B8, F9, 32, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtOpenProcess + 8 0000000077491518 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077491530 6 bytes [48, B8, 39, 1C, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtMapViewOfSection + 8 0000000077491538 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077491550 6 bytes [48, B8, F9, 1D, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection + 8 0000000077491558 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077491570 6 bytes [48, B8, 39, 5B, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtTerminateProcess + 8 0000000077491578 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077491620 6 bytes [48, B8, 39, 70, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtOpenSection + 8 0000000077491628 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077491650 6 bytes [48, B8, 79, 2F, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory + 8 0000000077491658 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077491670 6 bytes [48, B8, 79, 36, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 8 0000000077491678 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000077491700 6 bytes [48, B8, B9, 34, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtQueueApcThread + 8 0000000077491708 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077491750 6 bytes [48, B8, F9, 71, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtCreateSection + 8 0000000077491758 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 0000000077491780 6 bytes [48, B8, 39, 2A, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcessEx + 8 0000000077491788 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077491790 6 bytes [48, B8, B9, 26, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtCreateThread + 8 0000000077491798 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtSetValueKey 00000000774918b0 6 bytes [48, B8, 79, 75, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtSetValueKey + 8 00000000774918b8 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077491c80 6 bytes [48, B8, 79, 6E, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtCreateMutant + 8 0000000077491c88 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcess 0000000077491cd0 6 bytes [48, B8, 79, 28, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtCreateProcess + 8 0000000077491cd8 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077491d30 6 bytes [48, B8, F9, 24, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtCreateThreadEx + 8 0000000077491d38 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtLoadDriver 00000000774920a0 6 bytes [48, B8, B9, 5E, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtLoadDriver + 8 00000000774920a8 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread 00000000774927e0 6 bytes [48, B8, 39, 31, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtSetContextThread + 8 00000000774927e8 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 00000000774929a0 6 bytes [48, B8, 79, 60, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtSetSystemInformation + 8 00000000774929a8 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077492a80 6 bytes [48, B8, 79, 3D, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtSuspendProcess + 8 0000000077492a88 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077492a90 6 bytes [48, B8, B9, 3B, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtSuspendThread + 8 0000000077492a98 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077492aa0 6 bytes [48, B8, B9, 73, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtSystemDebugControl + 8 0000000077492aa8 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077492b80 6 bytes [48, B8, B9, 65, 06, 6C]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\ntdll.dll!NtVdmControl + 8 0000000077492b88 4 bytes [00, 00, 50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\system32\kernel32.dll!CreateToolhelp32Snapshot 0000000077321c10 12 bytes [48, B8, F9, 39, 06, 6C, 00, ...]
.text C:\windows\Explorer.EXE[5548] C:\windows\system32\kernel32.dll!CreateProcessInternalW 000000007733db80 12 bytes [48, B8, B9, 2D, 06, 6C, 00, ...]
.text C:\windows\Explorer.EXE[5548] C:\windows\system32\kernel32.dll!GetStartupInfoA + 1 0000000077340931 11 bytes [B8, F9, 63, 06, 6C, 00, 00, ...]
.text C:\windows\Explorer.EXE[5548] C:\windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fefd454350 12 bytes [48, B8, B9, 42, 06, 6C, 00, ...]
.text C:\windows\Explorer.EXE[5548] C:\windows\system32\KERNELBASE.dll!CreateRemoteThread + 1 000007fefd462871 8 bytes [B8, 39, 23, 06, 6C, 00, 00, ...]
.text C:\windows\Explorer.EXE[5548] C:\windows\system32\KERNELBASE.dll!CreateRemoteThread + 10 000007fefd46287a 2 bytes [50, C3]
.text C:\windows\Explorer.EXE[5548] C:\windows\system32\KERNELBASE.dll!CreateThread + 1 000007fefd4628b1 11 bytes [B8, F9, 40, 06, 6C, 00, 00, ...]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\sechost.dll!ControlService + 1 000007fefe95642d 11 bytes [B8, 79, 4B, 06, 6C, 00, 00, ...]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\sechost.dll!OpenServiceW 000007fefe956484 12 bytes [48, B8, 39, 46, 06, 6C, 00, ...]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 000007fefe956519 11 bytes [B8, 79, 52, 06, 6C, 00, 00, ...]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\sechost.dll!OpenServiceA 000007fefe956c34 12 bytes [48, B8, 79, 44, 06, 6C, 00, ...]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\sechost.dll!DeleteService + 1 000007fefe957ab5 11 bytes [B8, 39, 4D, 06, 6C, 00, 00, ...]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 000007fefe958b01 11 bytes [B8, F9, 47, 06, 6C, 00, 00, ...]
.text C:\windows\Explorer.EXE[5548] C:\windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 000007fefe958c39 11 bytes [B8, B9, 49, 06, 6C, 00, 00, ...]
.text C:\windows\Explorer.EXE[5548] C:\windows\system32\WS2_32.dll!connect 000007fefe9045c0 12 bytes [48, B8, 39, 54, 06, 6C, 00, ...] |