![]() |
Firefox, doppelt unterstrichene Wörter + Werbung + automatisch geöffnete Taps Hallo, seit gestern habe ich folgendes Problem: auf allen Webseiten erscheinen einzelne Wörter in grün und doppelt unterstrichen, sobald man mit der Maus darüber fährt öffnen sich kleine Taps mit Werbung. Desweiteren wird jede Webseite mit Werbebannern überzogen und es öffnen sich automatisch neue Taps in denen man aufgefordert wird bei Programmen Updates zu machen. Zudem hat sich das Verenprogramm YAC auf meinen Laptop geschlichen, welches mir nicht möglich ist zu löschen. Avast hab ich öfters meinen Laptop scanen lassen aber ohne Erfolg. Da ich ein reiner User bin hoffe ich, das mir hier jemand helfen kann. Anbei die wie in der Anleitung beschriebenen und gewünschten Textdateien. Danke |
Hi, Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. Ich kann auf Arbeit keine Anhänge öffnen, danke. ![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
|
Hi, okay sorry. defogger_disable by jpshortstuff (23.02.10.1) Log created at 12:01 on 07/10/2014 (Arne) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-10-2014 01 --- --- --- --- --- --- --- --- --- --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-10-2014 01 FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06-10-2014 01 GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-10-07 12:12:14 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Hitachi_HTS545050B9A300 rev.PB4OC60G 465,76GB Running: Gmer-19357.exe; Driver: C:\Users\Arne\AppData\Local\Temp\kxldrpow.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\Windows\System32\win32k.sys!EngSetLastError + 616 fffff960000a4ce4 8 bytes [04, B5, C5, 02, 80, F8, FF, ...] .text C:\Windows\System32\win32k.sys!W32pServiceTable fffff960000d3f00 7 bytes [80, 9D, F3, FF, 01, A9, F0] .text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff960000d3f08 3 bytes [C0, 06, 02] .text ... * 106 .text C:\Windows\System32\win32k.sys!EngGetProcessHandle + 400 fffff96000192c48 14 bytes [88, B7, C5, 02, 80, F8, FF, ...] ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000149970460 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000149970450 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000149970370 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000149970470 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 00000001499703e0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000149970320 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 00000001499703b0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000149970390 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 00000001499702e0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 00000001499702d0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000149970310 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 00000001499703c0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 00000001499703f0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000149970230 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000149970480 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 00000001499703a0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 00000001499702f0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000149970350 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000149970290 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 00000001499702b0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 00000001499703d0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000149970330 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000149970410 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000149970240 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 00000001499701e0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000149970250 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000149970490 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 00000001499704a0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000149970300 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000149970360 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 00000001499702a0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 00000001499702c0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000149970380 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000149970340 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000149970440 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000149970260 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000149970270 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000149970400 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 00000001499701f0 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000149970210 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000149970200 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000149970420 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000149970430 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000149970220 .text C:\Windows\system32\csrss.exe[400] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000149970280 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection |
0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\system32\wininit.exe[464] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\system32\wininit.exe[464] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000149970460 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000149970450 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000149970370 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000149970470 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 00000001499703e0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000149970320 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 00000001499703b0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000149970390 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 00000001499702e0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 00000001499702d0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000149970310 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 00000001499703c0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 00000001499703f0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000149970230 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000149970480 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 00000001499703a0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 00000001499702f0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000149970350 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000149970290 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 00000001499702b0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 00000001499703d0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000149970330 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000149970410 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000149970240 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 00000001499701e0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000149970250 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000149970490 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 00000001499704a0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000149970300 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000149970360 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 00000001499702a0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 00000001499702c0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000149970380 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000149970340 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000149970440 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000149970260 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000149970270 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000149970400 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 00000001499701f0 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000149970210 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000149970200 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000149970420 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000149970430 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000149970220 .text C:\Windows\system32\csrss.exe[476] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000149970280 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\system32\services.exe[520] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\system32\services.exe[520] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000100070460 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000100070450 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000100070370 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000100070470 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 00000001000703e0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000100070320 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 00000001000703b0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000100070390 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 00000001000702e0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 00000001000702d0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000100070310 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 00000001000703c0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 00000001000703f0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000100070230 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000100070480 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 00000001000703a0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 00000001000702f0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000100070350 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000100070290 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 00000001000702b0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 00000001000703d0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000100070330 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000100070410 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000100070240 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 00000001000701e0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000100070250 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000100070490 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 00000001000704a0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000100070300 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000100070360 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 00000001000702a0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 00000001000702c0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000100070380 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000100070340 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000100070440 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000100070260 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000100070270 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000100070400 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 00000001000701f0 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000100070210 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000100070200 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000100070420 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000100070430 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000100070220 .text C:\Windows\system32\lsass.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000100070280 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\system32\lsm.exe[544] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 |
.text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\system32\svchost.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\system32\svchost.exe[648] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\system32\winlogon.exe[700] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\system32\nvvsvc.exe[772] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[796] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\system32\svchost.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\system32\svchost.exe[840] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe[372] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\System32\svchost.exe[348] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\System32\svchost.exe[348] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\system32\svchost.exe[1056] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000100040460 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000100040450 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000100040370 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000100040470 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 00000001000403e0 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000100040320 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 00000001000403b0 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000100040390 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 00000001000402e0 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 00000001000402d0 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000100040310 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 00000001000403c0 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 00000001000403f0 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000100040230 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000100040480 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 00000001000403a0 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 00000001000402f0 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000100040350 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000100040290 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 00000001000402b0 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 00000001000403d0 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000100040330 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000100040410 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000100040240 |
.text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000100040250 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000100040490 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 00000001000404a0 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000100040300 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000100040360 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 00000001000402a0 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 00000001000402c0 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000100040380 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000100040340 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000100040440 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000100040260 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000100040270 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000100040400 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 00000001000401f0 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000100040210 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000100040200 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000100040420 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000100040430 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000100040220 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000100040280 .text C:\Windows\system32\AUDIODG.EXE[1148] C:\Windows\System32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000171b10460 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000171b10450 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000171b10370 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000171b10470 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000171b103e0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000171b10320 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000171b103b0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000171b10390 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000171b102e0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000171b102d0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000171b10310 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000171b103c0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000171b103f0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000171b10230 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000171b10480 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000171b103a0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000171b102f0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000171b10350 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000171b10290 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000171b102b0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000171b103d0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000171b10330 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000171b10410 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000171b10240 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000171b101e0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000171b10250 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000171b10490 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000171b104a0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000171b10300 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000171b10360 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000171b102a0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000171b102c0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000171b10380 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000171b10340 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000171b10440 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000171b10260 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000171b10270 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000171b10400 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000171b101f0 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000171b10210 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000171b10200 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000171b10420 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000171b10430 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000171b10220 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000171b10280 .text C:\Windows\system32\svchost.exe[1228] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1432] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\system32\nvvsvc.exe[1440] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000171b10460 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000171b10450 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000171b10370 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000171b10470 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000171b103e0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000171b10320 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000171b103b0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000171b10390 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000171b102e0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000171b102d0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000171b10310 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000171b103c0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000171b103f0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000171b10230 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000171b10480 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000171b103a0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000171b102f0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000171b10350 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000171b10290 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000171b102b0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000171b103d0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000171b10330 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000171b10410 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000171b10240 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000171b101e0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000171b10250 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000171b10490 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000171b104a0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000171b10300 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000171b10360 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000171b102a0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000171b102c0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000171b10380 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000171b10340 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000171b10440 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000171b10260 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000171b10270 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000171b10400 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000171b101f0 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000171b10210 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000171b10200 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000171b10420 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000171b10430 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000171b10220 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000171b10280 .text C:\Windows\system32\svchost.exe[1516] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000100070460 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000100070450 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000100070370 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000100070470 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 00000001000703e0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000100070320 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 00000001000703b0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000100070390 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 00000001000702e0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 00000001000702d0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000100070310 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 00000001000703c0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 00000001000703f0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000100070230 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000100070480 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 00000001000703a0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 00000001000702f0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000100070350 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000100070290 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 00000001000702b0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 00000001000703d0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000100070330 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000100070410 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000100070240 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 00000001000701e0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000100070250 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000100070490 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 00000001000704a0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000100070300 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000100070360 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 00000001000702a0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 00000001000702c0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000100070380 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000100070340 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000100070440 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000100070260 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000100070270 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000100070400 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 00000001000701f0 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000100070210 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000100070200 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000100070420 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000100070430 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000100070220 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000100070280 .text C:\Windows\system32\Dwm.exe[1848] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\Explorer.EXE[1884] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\Explorer.EXE[1884] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000171b10460 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000171b10450 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000171b10370 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000171b10470 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000171b103e0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000171b10320 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000171b103b0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000171b10390 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000171b102e0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000171b102d0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000171b10310 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000171b103c0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000171b103f0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000171b10230 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000171b10480 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000171b103a0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000171b102f0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000171b10350 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000171b10290 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000171b102b0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000171b103d0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000171b10330 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000171b10410 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000171b10240 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000171b101e0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000171b10250 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000171b10490 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000171b104a0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000171b10300 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000171b10360 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000171b102a0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000171b102c0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000171b10380 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000171b10340 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000171b10440 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000171b10260 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000171b10270 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000171b10400 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000171b101f0 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000171b10210 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000171b10200 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000171b10420 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000171b10430 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000171b10220 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000171b10280 .text C:\Windows\system32\svchost.exe[1276] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe[1488] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe[1488] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e81465 2 bytes [E8, 74] .text C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe[1488] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e814bb 2 bytes [E8, 74] .text ... * 2 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\system32\taskeng.exe[1496] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2116] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2232] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe[2356] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe[2420] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2468] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2468] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000074e81465 2 bytes [E8, 74] .text C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe[2468] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000074e814bb 2 bytes [E8, 74] .text ... * 2 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2612] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2612] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000074e81465 2 bytes [E8, 74] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[2612] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000074e814bb 2 bytes [E8, 74] .text ... * 2 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2652] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2652] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000074e81465 2 bytes [E8, 74] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2652] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000074e814bb 2 bytes [E8, 74] .text ... * 2 .text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2772] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[924] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] |
.text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000171b10460 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000171b10450 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000171b10370 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000171b10470 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000171b103e0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000171b10320 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000171b103b0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000171b10390 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000171b102e0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000171b102d0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000171b10310 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000171b103c0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000171b103f0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000171b10230 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000171b10480 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000171b103a0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000171b102f0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000171b10350 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000171b10290 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000171b102b0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000171b103d0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000171b10330 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000171b10410 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000171b10240 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000171b101e0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000171b10250 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000171b10490 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000171b104a0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000171b10300 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000171b10360 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000171b102a0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000171b102c0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000171b10380 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000171b10340 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000171b10440 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000171b10260 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000171b10270 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000171b10400 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000171b101f0 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000171b10210 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000171b10200 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000171b10420 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000171b10430 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000171b10220 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000171b10280 .text C:\Windows\system32\svchost.exe[3132] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\PROGRA~3\zoomify2\110~1.25\wzoomifyd.exe[3256] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\PROGRA~3\zoomify2\110~1.25\wzoomifyd.exe[3256] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e81465 2 bytes [E8, 74] .text C:\PROGRA~3\zoomify2\110~1.25\wzoomifyd.exe[3256] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e814bb 2 bytes [E8, 74] .text ... * 2 .text C:\PROGRA~3\zoomify2\110~1.25\zoomify.exe[3284] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\PROGRA~3\zoomify2\110~1.25\zoomify.exe[3284] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e81465 2 bytes [E8, 74] .text C:\PROGRA~3\zoomify2\110~1.25\zoomify.exe[3284] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e814bb 2 bytes [E8, 74] .text ... * 2 .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe[3388] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe[3496] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Program Files\iPod\bin\iPodService.exe[3560] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\system32\SearchIndexer.exe[3672] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\system32\wbem\wmiprvse.exe[3868] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[3380] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000171b10460 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000171b10450 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000171b10370 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000171b10470 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000171b103e0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000171b10320 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000171b103b0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000171b10390 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000171b102e0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000171b102d0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000171b10310 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000171b103c0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000171b103f0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000171b10230 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000171b10480 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000171b103a0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000171b102f0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000171b10350 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000171b10290 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000171b102b0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000171b103d0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000171b10330 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000171b10410 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000171b10240 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000171b101e0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000171b10250 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000171b10490 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000171b104a0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000171b10300 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000171b10360 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000171b102a0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000171b102c0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000171b10380 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000171b10340 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000171b10440 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000171b10260 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000171b10270 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000171b10400 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000171b101f0 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000171b10210 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000171b10200 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000171b10420 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000171b10430 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000171b10220 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000171b10280 .text C:\Windows\system32\svchost.exe[3096] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000076e60460 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000076e60450 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000076e60370 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000076e60470 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000076e603e0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000076e60320 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000076e603b0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000076e60390 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000076e602e0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000076e602d0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000076e60310 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000076e603c0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000076e603f0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000076e60230 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000076e60480 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000076e603a0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000076e602f0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000076e60350 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000076e60290 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000076e602b0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000076e603d0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000076e60330 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000076e60410 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000076e60240 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000076e601e0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000076e60250 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000076e60490 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000076e604a0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000076e60300 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000076e60360 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000076e602a0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000076e602c0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000076e60380 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000076e60340 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000076e60440 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000076e60260 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000076e60270 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000076e60400 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000076e601f0 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000076e60210 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000076e60200 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000076e60420 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000076e60430 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000076e60220 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000076e60280 .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4116] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[1940] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000076d01360 5 bytes JMP 0000000171b10460 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000076d013b0 5 bytes JMP 0000000171b10450 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000076d01510 5 bytes JMP 0000000171b10370 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000076d01560 5 bytes JMP 0000000171b10470 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000076d01570 5 bytes JMP 0000000171b103e0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000076d01620 5 bytes JMP 0000000171b10320 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076d01650 5 bytes JMP 0000000171b103b0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000076d01670 5 bytes JMP 0000000171b10390 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000076d016b0 5 bytes JMP 0000000171b102e0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000076d01730 5 bytes JMP 0000000171b102d0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000076d01750 5 bytes JMP 0000000171b10310 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000076d01790 5 bytes JMP 0000000171b103c0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000076d017e0 5 bytes JMP 0000000171b103f0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000076d01940 5 bytes JMP 0000000171b10230 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000076d01b00 5 bytes JMP 0000000171b10480 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000076d01b30 5 bytes JMP 0000000171b103a0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000076d01c10 5 bytes JMP 0000000171b102f0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000076d01c20 5 bytes JMP 0000000171b10350 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000076d01c80 5 bytes JMP 0000000171b10290 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000076d01d10 5 bytes JMP 0000000171b102b0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076d01d30 5 bytes JMP 0000000171b103d0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000076d01d40 5 bytes JMP 0000000171b10330 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000076d01db0 5 bytes JMP 0000000171b10410 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000076d01de0 5 bytes JMP 0000000171b10240 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000076d020a0 5 bytes JMP 0000000171b101e0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000076d02160 5 bytes JMP 0000000171b10250 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000076d02190 5 bytes JMP 0000000171b10490 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000076d021a0 5 bytes JMP 0000000171b104a0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000076d021d0 5 bytes JMP 0000000171b10300 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000076d021e0 5 bytes JMP 0000000171b10360 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000076d02240 5 bytes JMP 0000000171b102a0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000076d02290 5 bytes JMP 0000000171b102c0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000076d022c0 5 bytes JMP 0000000171b10380 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000076d022d0 5 bytes JMP 0000000171b10340 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000076d025c0 5 bytes JMP 0000000171b10440 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000076d027c0 5 bytes JMP 0000000171b10260 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000076d027d0 5 bytes JMP 0000000171b10270 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076d027e0 5 bytes JMP 0000000171b10400 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000076d029a0 5 bytes JMP 0000000171b101f0 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000076d029b0 5 bytes JMP 0000000171b10210 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000076d02a20 5 bytes JMP 0000000171b10200 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000076d02a80 5 bytes JMP 0000000171b10420 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000076d02a90 5 bytes JMP 0000000171b10430 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000076d02aa0 5 bytes JMP 0000000171b10220 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000076d02b80 5 bytes JMP 0000000171b10280 .text C:\Windows\System32\svchost.exe[3144] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 0000000076aeeecd 1 byte [62] .text C:\Users\Arne\Desktop\Gmer-19357.exe[4152] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007681a2ba 1 byte [62] .text C:\Users\Arne\Desktop\Gmer-19357.exe[4152] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074e81465 2 bytes [E8, 74] .text C:\Users\Arne\Desktop\Gmer-19357.exe[4152] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074e814bb 2 bytes [E8, 74] .text ... * 2 ---- Threads - GMER 2.1 ---- Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [852:488] 0000000076987587 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [852:2004] 000000006b6d0cb3 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [852:4672] 0000000076ee2e65 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [852:3404] 0000000076ee3e85 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [852:5260] 0000000076ee3e85 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [852:6068] 0000000076ee3e85 Thread C:\Windows\System32\svchost.exe [3144:3120] 000007fef0799688 ---- Processes - GMER 2.1 ---- Library C:\PROGRA~3\zoomify2\110~1.25\zoomifyl64.dll (*** suspicious ***) @ C:\Windows\system32\Dwm.exe [1848] (COMPANY_NAME)(2014-10-02 08:27:52) 000007fef1260000 Library C:\PROGRA~3\zoomify2\110~1.25\zoomifyl64.dll (*** suspicious ***) @ C:\Windows\Explorer.EXE [1884] (COMPANY_NAME)(2014-10-02 08:27:52) 000007fef1260000 Library C:\PROGRA~3\zoomify2\110~1.25\zoomifyl32.dll (*** suspicious ***) @ C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe [1488] (COMPANY_NAME)(2014-10-02 08:26:24) 0000000066ec0000 Process C:\PROGRA~3\zoomify2\110~1.25\wzoomifyd.exe (*** suspicious ***) @ C:\PROGRA~3\zoomify2\110~1.25\wzoomifyd.exe [3256] (Zoomify Agent)(2014-10-0 0000000000400000 Process C:\PROGRA~3\zoomify2\110~1.25\zoomify.exe (*** suspicious ***) @ C:\PROGRA~3\zoomify2\110~1.25\zoomify.exe [3284] (Zoomify Agent)(2014-10-02 08:27: 0000000001080000 Library C:\PROGRA~3\zoomify2\110~1.25\zoomifyutil32.dll (*** suspicious ***) @ C:\PROGRA~3\zoomify2\110~1.25\zoomify.exe [3284] (Zoomify Agent)(2014- 0000000072700000 Process C:\PROGRA~3\zoomify2\110~1.25\zoomifyD32.exe (*** suspicious ***) @ C:\PROGRA~3\zoomify2\110~1.25\zoomifyD32.exe [4280] (Zoomify Agent)(2014- 0000000000220000 Library C:\PROGRA~3\zoomify2\110~1.25\zoomifyutil32.dll (*** suspicious ***) @ C:\PROGRA~3\zoomify2\110~1.25\zoomifyD32.exe [4280] (Zoomify Agent) 0000000072700000 Library C:\PROGRA~3\zoomify2\110~1.25\zoomifyl32.dll (*** suspicious ***) @ C:\PROGRA~3\zoomify2\110~1.25\zoomifyD32.exe [4280] (COMPANY_NAME)(2014-1 0000000066ec0000 Process C:\PROGRA~3\zoomify2\110~1.25\zoomifyL64.exe (*** suspicious ***) @ C:\PROGRA~3\zoomify2\110~1.25\zoomifyL64.exe [4552] (Zoomify Agent)(2014- 000000013f2d0000 Library C:\PROGRA~3\zoomify2\110~1.25\zoomifyl64.dll (*** suspicious ***) @ C:\PROGRA~3\zoomify2\110~1.25\zoomifyL64.exe [4552] (COMPANY_NAME)(2014-1 000007fef1260000 Process C:\PROGRA~3\zoomify2\110~1.25\zoomifyL32.exe (*** suspicious ***) @ C:\PROGRA~3\zoomify2\110~1.25\zoomifyL32.exe [4692] (Zoomify Agent)(2014- 00000000011e0000 Library C:\PROGRA~3\zoomify2\110~1.25\zoomifyl32.dll (*** suspicious ***) @ C:\PROGRA~3\zoomify2\110~1.25\zoomifyL32.exe [4692] (COMPANY_NAME)(2014-1 0000000066ec0000 Library C:\PROGRA~3\zoomify2\110~1.25\zoomifyl32.dll (*** suspicious ***) @ C:\Users\Arne\Desktop\Gmer-19357.exe [4152] (COMPANY_NAME)(2014-10-02 08:26:24) 0000000066ec0000 ---- EOF - GMER 2.1 ---- |
hi, Scan mit Combofix
|
Combofix Logfile: Code: ComboFix 14-10-04.01 - Arne 08.10.2014 13:25:28.1.2 - x64 A36C5E4F47E84449FF07ED3517B43A31 Hi, ich hoffe es ist das was benötigt wird?! Gruss |
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
Moin Moin, schon mal vielen Dank. Es haben sich schon erste Erfolge eingestellt, die unterstrichenen Wörter, die Dauerwerbung auf jeder Webseite so die neuen Taps sind bereits verschwunden. Auch läuft die Kiste wieder schneller!AdwCleaner Logfile: Code: # AdwCleaner v3.311 - Bericht erstellt am 06/10/2014 um 23:11:40 AdwCleaner Logfile: Code: # AdwCleaner v3.311 - Bericht erstellt am 09/10/2014 um 11:55:25 Malwarebytes Anti-Malware Malwarebytes | Free Anti-Malware & Internet Security Software Suchlauf Datum: 09.10.2014 Suchlauf-Zeit: 11:30:04 Logdatei: mbam.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.10.09.04 Rootkit Datenbank: v2014.10.08.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Arne Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 359534 Verstrichene Zeit: 13 Min, 39 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 11 PUP.Optional.Snapdo.T, HKU\S-1-5-21-856369245-1405169768-1277596959-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [01a71cf6a3d923133efad7fef01237c9], PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}, Löschen bei Neustart, [24842ee46d0ffe38d7279dfba0624cb4], PUP.Optional.MBot.A, HKLM\SOFTWARE\WOW6432NODE\MYBESTOFFERSTODAY, In Quarantäne, [5157848e7ffd0e281ec402176f9423dd], PUP.Optional.RocketTab.A, HKLM\SOFTWARE\WOW6432NODE\RocketTab, In Quarantäne, [acfc64ae3d3f1026826a0e07b05319e7], PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SmdmF, In Quarantäne, [7a2e1bf74b3136006bc62eec26dda65a], PUP.Optional.Zoomify.A, HKLM\SOFTWARE\WOW6432NODE\zoomify, In Quarantäne, [24843ed4c1bbb4821051030e9172e61a], PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, In Quarantäne, [50586ca6a8d44de923a6db45d42f21df], PUP.Optional.Zoomify.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\wzoomifyd, In Quarantäne, [9216769c93e9e94dafb030e1847f9e62], PUP.Optional.Zoomify.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\zoomify, In Quarantäne, [cddb30e2e29ad85ec19fe22f897afd03], PUP.Optional.CrossRider.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HD-Quality-v3V05.10, In Quarantäne, [e6c2fa186d0fea4cc8051ff3768d758b], PUP.Optional.RocketTab.A, HKU\S-1-5-21-856369245-1405169768-1277596959-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\RocketTabInstalled, In Quarantäne, [edbbf02255273ef8935ba273df240af6], Registrierungswerte: 3 PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [50586ca6a8d44de923a6db45d42f21df] PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|quick_start@gmail.com, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\s2k9j764.default\extensions\quick_start@gmail.com, In Quarantäne, [62463fd380fc5dd96617291346bdfa06] PUP.Optional.QuickStart.A, HKU\S-1-5-21-856369245-1405169768-1277596959-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, quick_start@gmail.com, In Quarantäne, [aafe6ba777052115782e73b3a360b050] Registrierungsdaten: 1 PUP.Optional.SnapDo.A, HKU\S-1-5-21-856369245-1405169768-1277596959-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRaklm31XHoHPezyxuXcoLyh8uf9z36AtrHb4-NUwcB-250bU1K4xXyleDmwEyhBSBo3ArDiGT3qRktIHmaJaVLnxYQGkJ6NUh2SjzfBaTmy_UHxzwW5EdaI39VIOF4iplM4LcLJcaCxgsILTtzWynYe7FDRP8Hscat77fd0zyadcr0UWCgS_r3LGwQ,,&q={s earchTerms}, Gut: (Google), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRaklm31XHoHPezyxuXcoLyh8uf9z36AtrHb4-NUwcB-250bU1K4xXyleDmwEyhBSBo3ArDiGT3qRktIHmaJaVLnxYQGkJ6NUh2SjzfBaTmy_UHxzwW5EdaI39VIOF4iplM4LcLJcaCxgsILTtzWynYe7FDRP8Hscat77fd0zyadcr0UWCgS_r3LGwQ,,&q={s earchTerms}),Ersetzt,[5a4ece44ee8e0f27f38bbb5358adec14] Ordner: 3 PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2, Löschen bei Neustart, [189065ad304c0d298f89987751b22cd4], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25, Löschen bei Neustart, [189065ad304c0d298f89987751b22cd4], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\content, In Quarantäne, [189065ad304c0d298f89987751b22cd4], Dateien: 26 PUP.Optional.HDQuality.A, C:\Users\Arne\AppData\Roaming\KZXMT.exe, In Quarantäne, [dcccdc369ededd598f8731937f8234cc], PUP.Optional.HDQuality.A, C:\Users\Arne\AppData\Roaming\NMBDOU.exe, In Quarantäne, [4d5be42e3448ce68aa6cdde717ead42c], PUP.Optional.Amonetize, C:\Users\Arne\Downloads\czech.hunter.4.full.episode.free__6629_i1342853153_il32438.exe, In Quarantäne, [fdab070b1369f73f947a5565e51cf60a], PUP.Optional.DomaIQ, C:\Users\Arne\Downloads\Setup(2).exe, In Quarantäne, [f1b78191a6d6fe38a0071b224ab69a66], PUP.Optional.OutBrowse, C:\Users\Arne\Downloads\Update_Mozilla_Firefox.exe, In Quarantäne, [dace4dc52b510630e99fb80d3cc525db], PUP.Optional.Somoto.A, C:\Users\Arne\Downloads\FLVPlayerSetup-Na2IXsKeB.exe, In Quarantäne, [3c6cb260215bf34331ec513fd92b27d9], PUP.Optional.Verti, C:\Users\Arne\Downloads\MediaPlayerClassic.exe, In Quarantäne, [adfb45cd0c70ce6856980ce4f50fe31d], PUP.Optional.RocketTab.A, C:\Windows\System32\Tasks\RocketTab, In Quarantäne, [11977d9505771d1914dcf52042c1639d], PUP.Optional.RocketTab.A, C:\Windows\System32\Tasks\RocketTab Update Task, In Quarantäne, [6741d53da9d359ddf6fa0312847fe31d], PUP.Optional.Trovi.A, C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.trovi.com_0.localstorage, In Quarantäne, [deca030f36465dd95eb663cc5da635cb], PUP.Optional.Trovi.A, C:\Users\Arne\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.trovi.com_0.localstorage-journal, In Quarantäne, [edbbc44e80fc43f344d0f43bee15728e], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\wzoomifyd.exe, Löschen bei Neustart, [9216769c93e9e94dafb030e1847f9e62], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\zoomify.exe, Löschen bei Neustart, [cddb30e2e29ad85ec19fe22f897afd03], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\logo.ico, In Quarantäne, [189065ad304c0d298f89987751b22cd4], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\Uninstaller.exe, In Quarantäne, [189065ad304c0d298f89987751b22cd4], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\zoomifyD32.exe, Löschen bei Neustart, [189065ad304c0d298f89987751b22cd4], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\zoomifyL32.dll, Löschen bei Neustart, [189065ad304c0d298f89987751b22cd4], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\zoomifyL32.exe, Löschen bei Neustart, [189065ad304c0d298f89987751b22cd4], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\zoomifyL64.dll, Löschen bei Neustart, [189065ad304c0d298f89987751b22cd4], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\zoomifyL64.exe, Löschen bei Neustart, [189065ad304c0d298f89987751b22cd4], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\zoomifyutil32.dll, Löschen bei Neustart, [189065ad304c0d298f89987751b22cd4], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\content\dgapi.js, In Quarantäne, [189065ad304c0d298f89987751b22cd4], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\content\dgmain_app_bg.js, In Quarantäne, [189065ad304c0d298f89987751b22cd4], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\content\dgmain_app_cs.js, In Quarantäne, [189065ad304c0d298f89987751b22cd4], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\content\jquery4toolbar.js, In Quarantäne, [189065ad304c0d298f89987751b22cd4], PUP.Optional.Zoomify.A, C:\ProgramData\zoomify2\1.1.0.25\content\witmain.js, In Quarantäne, [189065ad304c0d298f89987751b22cd4], Physische Sektoren: 0 (No malicious items detected) (end)JRT Logfile: Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-10-2014 01 |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=696c231f46935a46acbbf2f392256d14 # engine=20532 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2014-10-10 11:14:39 # local_time=2014-10-10 01:14:39 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 100 90 389866 23921275 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 170951 164569529 0 0 # scanned=178968 # found=28 # cleaned=0 # scan_time=6168 sh=9413821E4285C46DAF48156B472065FC2D763FE8 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Arne\AppData\Roaming\KZXMT" sh=DDD7E789E67132CF6C5D8169B2F46E3498FCA60F ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Arne\AppData\Roaming\NMBDOU" sh=63C3BEB91F90F464E78DBF5F4410FAC0610DC275 ft=1 fh=0db8354eb1258fa4 vn="Variante von Win32/Verti.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Arne\Downloads\TinyPlayerInstaller.exe" sh=D27161080F7B2BC2B5E03B915BC16BC4E17BE5AF ft=1 fh=0036f0974d4feb3d vn="Variante von Win32/WinloadSDA.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Arne\Downloads\trz2BF3.tmp" sh=E5AD99CE7C7362CA566156033ECB0F04F9437CA7 ft=1 fh=f45d83e01e1c8734 vn="Win32/Toolbar.Conduit.Q evtl. unerwünschte Anwendung" ac=I fn="D:\alte_platte_C_2014\AppData\Local\Conduit\CT3031778\SFT_de3AutoUpdateHelper.exe" sh=3803074FE242DCDB843A75F6A057AC1650AA5623 ft=1 fh=b98be267fa595ad1 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="D:\alte_platte_C_2014\AppData\LocalLow\ConduitEngine\ConduitEngin.dll" sh=37E166E756A9AB25AF72B1B3281B9BC189818A47 ft=1 fh=a195dc62459b977b vn="Variante von Win32/Toolbar.Conduit.P evtl. unerwünschte Anwendung" ac=I fn="D:\alte_platte_C_2014\AppData\LocalLow\ConduitEngine\ldrConduitEngin.dll" sh=37E166E756A9AB25AF72B1B3281B9BC189818A47 ft=1 fh=a195dc62459b977b vn="Variante von Win32/Toolbar.Conduit.P evtl. unerwünschte Anwendung" ac=I fn="D:\alte_platte_C_2014\AppData\LocalLow\SFT_de3\ldrtbSFT_.dll" sh=3803074FE242DCDB843A75F6A057AC1650AA5623 ft=1 fh=b98be267fa595ad1 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="D:\alte_platte_C_2014\AppData\LocalLow\SFT_de3\tbSFT_.dll" sh=FF58643464A06A17B4FE7BC20EF077A4A63CA6D0 ft=1 fh=3ed4f76e1eec9c5a vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung" ac=I fn="D:\alte_platte_C_2014\AppData\Roaming\Mozilla\Firefox\Profiles\nsifqfxv.default\extensions\toolbar@ask.com\plugins\npAviraCallingID.dll" sh=EB4743944995A18BEB3FB34AE99AA7FCFF0B6982 ft=1 fh=5d41c12eaf2b4b0d vn="Variante von Win32/DomaIQ.AN evtl. unerwünschte Anwendung" ac=I fn="D:\alte_platte_C_2014\Downloads\setup player.exe" sh=AD0A3C863C4C1C8A89BA608C09641E6D6577B4C4 ft=1 fh=81f1eef43efab2d1 vn="Variante von Win32/Bundlore.B evtl. unerwünschte Anwendung" ac=I fn="D:\alte_platte_C_2014\Downloads\setup.exe" sh=265A7FB8A5040ED34A4EAC850EFBC552AA00ED33 ft=1 fh=848d7299ba17e799 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\Ask.com\AviraBrowserSecurity.exe" sh=42C894591A3B80C428BCFF682557DC35E30538DA ft=1 fh=c187413b38fccc64 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\Ask.com\AviraCallingIDhelper.dll" sh=441CA4F8BCC91C38129B9B3D00D3B9DD934A7B78 ft=1 fh=7a34b03f9074fe72 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\Ask.com\GenericAskToolbar.dll" sh=1B1593688B0B4D69E943E15CA143444B7325C691 ft=1 fh=6272ea900fd9b86d vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\Ask.com\precache.exe" sh=5C3130B2550021868AD007877043D304C525AB11 ft=1 fh=33092ccccfa2de45 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\Ask.com\SaUpdate.exe" sh=7CA12F77F77B5A6A43A9AC9C1F399847F09508D7 ft=1 fh=eb0854eca8537d9d vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\Ask.com\UpdateTask.exe" sh=935FE2F938CBE6F835A0A99D82309E50807511F7 ft=1 fh=69794c8bfd127010 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\Ask.com\Updater\Updater.exe" sh=71435DDB11E00D0243380C4902324853FE4ECE8F ft=1 fh=12b0cd2dde452d65 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\Avira\AntiVir Desktop\apnic.dll" sh=FFA8B6510D624A55F3EB7FFD6D5221A44944681C ft=1 fh=3386eb0d6ed0e5e1 vn="Variante von Win32/Bundled.Toolbar.Ask.G potenziell unsichere Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\Avira\AntiVir Desktop\apnstub.exe" sh=1A3F14C0A66F9AF050D1F34FBACBAADC31751A07 ft=1 fh=2704a03a0f47b728 vn="Variante von Win32/Bundled.Toolbar.Ask potenziell unsichere Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\Avira\AntiVir Desktop\apntoolbarinstaller.exe" sh=4B553651EF610C0614F8393D6C25ABA0A8F09ECA ft=1 fh=92ef1bb072edf568 vn="Variante von Win32/Bundled.Toolbar.Ask.D potenziell unsichere Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\Avira\AntiVir Desktop\Offercast_AVIRAV7_.exe" sh=1670BA69124E9B584AE4D068E6770DF33A97ED0A ft=1 fh=445bf9fd42033e60 vn="Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\Conduit\Community Alerts\Alert.dll" sh=3803074FE242DCDB843A75F6A057AC1650AA5623 ft=1 fh=b98be267fa595ad1 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\ConduitEngine\ConduitEngin.dll" sh=E5AD99CE7C7362CA566156033ECB0F04F9437CA7 ft=1 fh=f45d83e01e1c8734 vn="Win32/Toolbar.Conduit.Q evtl. unerwünschte Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\ConduitEngine\ConduitEngineHelper.exe" sh=37E166E756A9AB25AF72B1B3281B9BC189818A47 ft=1 fh=a195dc62459b977b vn="Variante von Win32/Toolbar.Conduit.P evtl. unerwünschte Anwendung" ac=I fn="D:\alte_platte_D_2014\Program Files (x86)\ConduitEngine\ldrConduitEngin.dll" sh=EA244E84E1468A6AF4741F2184E113A16F833D8B ft=1 fh=a9c73d0d07b22a58 vn="Win32/Bundled.Toolbar.Google.D potenziell unsichere Anwendung" ac=I fn="D:\bitte_nicht_löschen\ccsetup402.exe" Results of screen317's Security Check version 0.99.87 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus out of date! `````````Anti-malware/Other Utilities Check:````````` MVPS Hosts File Adobe Flash Player 15.0.0.152 Adobe Reader XI Mozilla Firefox (32.0.3) Google Chrome 37.0.2062.120 Google Chrome 37.0.2062.124 ````````Process Check: objlist.exe by Laurent```````` Spybot Teatimer.exe is disabled! AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-10-2014 01 --- --- --- --- --- --- Moin Moin, soweit ist alles okay. Nur das sich Firefox zwischendurch mal aufhängt und das ich dieses YAC (Yet Another Cleaner) nicht mehr loswerde. |
Zitat:
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: C:\Users\Arne\AppData\Roaming\KZXMT Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
|
Moin Moin, dieses YAC ist mit einer Verknüpfung auf dem Desktop aber nicht unter Systemsteuerung zu deinstalieren vorhanden. Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 06-10-2014 01 Ran by Arne at 2014-10-11 12:54:30 Run:1 Running from C:\Users\Arne\Desktop Loaded Profiles: Arne & UpdatusUser (Available profiles: Arne & UpdatusUser) Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Arne\AppData\Roaming\KZXMT C:\Users\Arne\AppData\Roaming\NMBDOU Emptytemp: ***************** C:\Users\Arne\AppData\Roaming\KZXMT => Moved successfully. C:\Users\Arne\AppData\Roaming\NMBDOU => Moved successfully. EmptyTemp: => Removed 550.6 MB temporary data. The system needed a reboot. ==== End of Fixlog ==== |
Alle Zeitangaben in WEZ +1. Es ist jetzt 13:09 Uhr. |
Copyright ©2000-2025, Trojaner-Board