GMER Teil 1: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-06-29 06:26:53
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002c WDC_WD10 rev.80.0 931,51GB
Running: Gmer-19357.exe; Driver: C:\Users\Martin\AppData\Local\Temp\awdyqpoc.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable fffff960001fbd00 15 bytes [00, A9, F3, 01, 80, 64, 6D, ...]
.text C:\WINDOWS\System32\win32k.sys!W32pServiceTable + 16 fffff960001fbd10 11 bytes [00, 91, FC, FF, 00, BF, CA, ...]
---- User code sections - GMER 2.1 ----
.text C:\WINDOWS\system32\services.exe[744] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\services.exe[744] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\services.exe[744] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\system32\services.exe[744] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\system32\services.exe[744] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\system32\services.exe[744] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\system32\lsass.exe[752] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\lsass.exe[752] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\lsass.exe[752] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\system32\lsass.exe[752] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\system32\lsass.exe[752] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\system32\lsass.exe[752] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!MoveWindow 00007ff8162011d0 6 bytes {JMP QWORD [RIP+0x7bee60]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SetParent 00007ff816201220 6 bytes {JMP QWORD [RIP+0x79ee10]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!GetKeyboardState 00007ff816201230 6 bytes {JMP QWORD [RIP+0x71ee00]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SendInput 00007ff816201240 6 bytes {JMP QWORD [RIP+0x6fedf0]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SetClipboardViewer 00007ff8162014e0 6 bytes {JMP QWORD [RIP+0x7deb50]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!BlockInput 00007ff816201530 6 bytes {JMP QWORD [RIP+0x7feb00]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!RegisterHotKey 00007ff816201c90 6 bytes {JMP QWORD [RIP+0x83e3a0]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!RegisterRawInputDevices 00007ff816201cb0 6 bytes {JMP QWORD [RIP+0x77e380]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!PostMessageW 00007ff8162033f0 6 bytes {JMP QWORD [RIP+0x3bcc40]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!PostThreadMessageW 00007ff8162035a0 6 bytes {JMP QWORD [RIP+0x3fca90]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutW + 1 00007ff816204311 5 bytes {JMP QWORD [RIP+0x47bd20]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoW 00007ff8162054e0 6 bytes {JMP QWORD [RIP+0x87ab50]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SendMessageW 00007ff816205720 6 bytes {JMP QWORD [RIP+0x43a910]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackW 00007ff8162062b0 6 bytes {JMP QWORD [RIP+0x4b9d80]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW 00007ff816206390 6 bytes {JMP QWORD [RIP+0x319ca0]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SetWindowLongW 00007ff8162093d0 6 bytes {JMP QWORD [RIP+0x376c60]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!mouse_event 00007ff816209f00 6 bytes {JMP QWORD [RIP+0x2d6130]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW 00007ff81620b7f0 3 bytes [FF, 25, 40]
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW + 4 00007ff81620b7f4 2 bytes [69, 00]
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!GetKeyState + 1 00007ff81620fd81 5 bytes {JMP QWORD [RIP+0x7302b0]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoA 00007ff816213740 6 bytes {JMP QWORD [RIP+0x84c8f0]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SetWindowLongA 00007ff816213c60 5 bytes [FF, 25, D0, C3, 34]
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!EnableWindow 00007ff816214610 6 bytes {JMP QWORD [RIP+0x88ba20]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!GetAsyncKeyState 00007ff816214b80 6 bytes {JMP QWORD [RIP+0x74b4b0]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SetWinEventHook + 1 00007ff816217101 5 bytes {JMP QWORD [RIP+0x328f30]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!PostThreadMessageA 00007ff8162255b0 6 bytes {JMP QWORD [RIP+0x3baa80]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!PostMessageA 00007ff816225920 6 bytes {JMP QWORD [RIP+0x37a710]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SendMessageA 00007ff816226190 6 bytes {JMP QWORD [RIP+0x3f9ea0]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!ExitWindowsEx 00007ff816234520 6 bytes {JMP QWORD [RIP+0x88bb10]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageW 00007ff816236480 6 bytes {JMP QWORD [RIP+0x6a9bb0]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageA 00007ff81623c620 6 bytes {JMP QWORD [RIP+0x643a10]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!GetClipboardData 00007ff81623efb0 6 bytes {JMP QWORD [RIP+0x7e1080]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutA 00007ff81623f600 6 bytes {JMP QWORD [RIP+0x420a30]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA 00007ff816260f60 6 bytes {JMP QWORD [RIP+0x29f0d0]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!keybd_event 00007ff816289620 6 bytes {JMP QWORD [RIP+0x236a10]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageA 00007ff816290f30 6 bytes {JMP QWORD [RIP+0x62f100]}
.text C:\WINDOWS\system32\svchost.exe[836] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackA 00007ff8162918f0 6 bytes {JMP QWORD [RIP+0x40e740]}
.text C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\system32\svchost.exe[880] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\system32\nvvsvc.exe[1000] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\nvvsvc.exe[1000] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\nvvsvc.exe[1000] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156200d8
.text C:\WINDOWS\system32\nvvsvc.exe[1000] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0xaf6ce0]}
.text C:\WINDOWS\system32\nvvsvc.exe[1000] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0xcb5b10]}
.text C:\WINDOWS\system32\nvvsvc.exe[1000] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0xaf4080]}
.text C:\WINDOWS\system32\svchost.exe[1132] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\svchost.exe[1132] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\svchost.exe[1132] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\system32\svchost.exe[1132] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\system32\svchost.exe[1132] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\system32\svchost.exe[1132] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!MoveWindow 00007ff8162011d0 6 bytes {JMP QWORD [RIP+0x7aee60]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SetParent 00007ff816201220 4 bytes [FF, 25, 10, EE]
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SetParent + 5 00007ff816201225 1 byte [00]
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!GetKeyboardState 00007ff816201230 6 bytes {JMP QWORD [RIP+0x70ee00]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SendInput 00007ff816201240 6 bytes {JMP QWORD [RIP+0x6eedf0]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SetClipboardViewer 00007ff8162014e0 6 bytes {JMP QWORD [RIP+0x7ceb50]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!BlockInput 00007ff816201530 6 bytes {JMP QWORD [RIP+0x7eeb00]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!RegisterHotKey 00007ff816201c90 6 bytes {JMP QWORD [RIP+0x82e3a0]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!RegisterRawInputDevices 00007ff816201cb0 6 bytes {JMP QWORD [RIP+0x76e380]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!PostMessageW 00007ff8162033f0 6 bytes {JMP QWORD [RIP+0x3acc40]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!PostThreadMessageW 00007ff8162035a0 6 bytes {JMP QWORD [RIP+0x3eca90]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutW + 1 00007ff816204311 5 bytes {JMP QWORD [RIP+0x46bd20]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoW 00007ff8162054e0 6 bytes {JMP QWORD [RIP+0x86ab50]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SendMessageW 00007ff816205720 6 bytes {JMP QWORD [RIP+0x42a910]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackW 00007ff8162062b0 6 bytes {JMP QWORD [RIP+0x4a9d80]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW 00007ff816206390 6 bytes {JMP QWORD [RIP+0x309ca0]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SetWindowLongW 00007ff8162093d0 6 bytes {JMP QWORD [RIP+0x366c60]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!mouse_event 00007ff816209f00 6 bytes {JMP QWORD [RIP+0x2c6130]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW 00007ff81620b7f0 3 bytes [FF, 25, 40]
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW + 4 00007ff81620b7f4 2 bytes [68, 00]
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!GetKeyState + 1 00007ff81620fd81 5 bytes {JMP QWORD [RIP+0x7202b0]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoA 00007ff816213740 6 bytes {JMP QWORD [RIP+0x83c8f0]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SetWindowLongA 00007ff816213c60 5 bytes [FF, 25, D0, C3, 33]
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!EnableWindow 00007ff816214610 6 bytes {JMP QWORD [RIP+0x87ba20]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!GetAsyncKeyState 00007ff816214b80 6 bytes {JMP QWORD [RIP+0x73b4b0]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SetWinEventHook + 1 00007ff816217101 5 bytes {JMP QWORD [RIP+0x318f30]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!PostThreadMessageA 00007ff8162255b0 6 bytes {JMP QWORD [RIP+0x3aaa80]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!PostMessageA 00007ff816225920 6 bytes {JMP QWORD [RIP+0x36a710]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SendMessageA 00007ff816226190 6 bytes {JMP QWORD [RIP+0x3e9ea0]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!ExitWindowsEx 00007ff816234520 6 bytes {JMP QWORD [RIP+0x87bb10]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageW 00007ff816236480 6 bytes {JMP QWORD [RIP+0x699bb0]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageA 00007ff81623c620 6 bytes {JMP QWORD [RIP+0x633a10]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!GetClipboardData 00007ff81623efb0 6 bytes {JMP QWORD [RIP+0x7d1080]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutA 00007ff81623f600 6 bytes {JMP QWORD [RIP+0x410a30]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA 00007ff816260f60 6 bytes {JMP QWORD [RIP+0x28f0d0]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!keybd_event 00007ff816289620 6 bytes {JMP QWORD [RIP+0x226a10]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageA 00007ff816290f30 6 bytes {JMP QWORD [RIP+0x61f100]}
.text C:\WINDOWS\System32\svchost.exe[1220] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackA 00007ff8162918f0 6 bytes {JMP QWORD [RIP+0x3fe740]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\RPCRT4.dll!RpcServerRegisterIf3 00007ff815e74fc0 6 bytes {JMP QWORD [RIP+0x50b070]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\RPCRT4.dll!RpcServerRegisterIfEx 00007ff815e8fe20 6 bytes {JMP QWORD [RIP+0x350210]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!MoveWindow 00007ff8162011d0 6 bytes {JMP QWORD [RIP+0x7bee60]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SetParent 00007ff816201220 6 bytes {JMP QWORD [RIP+0x79ee10]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!GetKeyboardState 00007ff816201230 6 bytes {JMP QWORD [RIP+0x71ee00]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SendInput 00007ff816201240 6 bytes {JMP QWORD [RIP+0x6fedf0]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SetClipboardViewer 00007ff8162014e0 6 bytes {JMP QWORD [RIP+0x7deb50]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!BlockInput 00007ff816201530 6 bytes {JMP QWORD [RIP+0x7feb00]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!RegisterHotKey 00007ff816201c90 6 bytes {JMP QWORD [RIP+0x83e3a0]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!RegisterRawInputDevices 00007ff816201cb0 6 bytes {JMP QWORD [RIP+0x77e380]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!PostMessageW 00007ff8162033f0 6 bytes {JMP QWORD [RIP+0x3bcc40]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!PostThreadMessageW 00007ff8162035a0 6 bytes {JMP QWORD [RIP+0x3fca90]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutW + 1 00007ff816204311 5 bytes {JMP QWORD [RIP+0x47bd20]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoW 00007ff8162054e0 6 bytes {JMP QWORD [RIP+0x87ab50]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SendMessageW 00007ff816205720 6 bytes {JMP QWORD [RIP+0x43a910]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackW 00007ff8162062b0 6 bytes {JMP QWORD [RIP+0x4b9d80]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW 00007ff816206390 6 bytes {JMP QWORD [RIP+0x319ca0]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SetWindowLongW 00007ff8162093d0 6 bytes {JMP QWORD [RIP+0x376c60]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!mouse_event 00007ff816209f00 6 bytes {JMP QWORD [RIP+0x2d6130]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW 00007ff81620b7f0 3 bytes [FF, 25, 40]
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW + 4 00007ff81620b7f4 2 bytes [69, 00]
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!GetKeyState + 1 00007ff81620fd81 5 bytes {JMP QWORD [RIP+0x7302b0]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoA 00007ff816213740 6 bytes {JMP QWORD [RIP+0x84c8f0]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SetWindowLongA 00007ff816213c60 5 bytes [FF, 25, D0, C3, 34]
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!EnableWindow 00007ff816214610 6 bytes {JMP QWORD [RIP+0x88ba20]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!GetAsyncKeyState 00007ff816214b80 6 bytes {JMP QWORD [RIP+0x74b4b0]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SetWinEventHook + 1 00007ff816217101 5 bytes {JMP QWORD [RIP+0x328f30]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!PostThreadMessageA 00007ff8162255b0 6 bytes {JMP QWORD [RIP+0x3baa80]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!PostMessageA 00007ff816225920 6 bytes {JMP QWORD [RIP+0x37a710]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SendMessageA 00007ff816226190 6 bytes {JMP QWORD [RIP+0x3f9ea0]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!ExitWindowsEx 00007ff816234520 6 bytes {JMP QWORD [RIP+0x88bb10]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageW 00007ff816236480 6 bytes {JMP QWORD [RIP+0x6a9bb0]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageA 00007ff81623c620 6 bytes {JMP QWORD [RIP+0x643a10]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!GetClipboardData 00007ff81623efb0 6 bytes {JMP QWORD [RIP+0x7e1080]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutA 00007ff81623f600 6 bytes {JMP QWORD [RIP+0x420a30]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA 00007ff816260f60 6 bytes {JMP QWORD [RIP+0x29f0d0]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!keybd_event 00007ff816289620 6 bytes {JMP QWORD [RIP+0x236a10]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageA 00007ff816290f30 6 bytes {JMP QWORD [RIP+0x62f100]}
.text C:\WINDOWS\system32\svchost.exe[1244] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackA 00007ff8162918f0 6 bytes {JMP QWORD [RIP+0x40e740]}
.text C:\WINDOWS\system32\svchost.exe[1292] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\svchost.exe[1292] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\svchost.exe[1292] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\system32\svchost.exe[1292] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\system32\svchost.exe[1292] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\system32\svchost.exe[1292] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\System32\svchost.exe[1340] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\System32\svchost.exe[1340] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\System32\svchost.exe[1340] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\System32\svchost.exe[1340] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\System32\svchost.exe[1340] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\System32\svchost.exe[1340] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\system32\svchost.exe[1616] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\svchost.exe[1616] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\svchost.exe[1616] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\system32\svchost.exe[1616] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\system32\svchost.exe[1616] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\system32\svchost.exe[1616] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\system32\svchost.exe[1616] C:\WINDOWS\system32\RPCRT4.dll!RpcServerRegisterIf3 00007ff815e74fc0 6 bytes {JMP QWORD [RIP+0x50b070]}
.text C:\WINDOWS\system32\svchost.exe[1616] C:\WINDOWS\system32\RPCRT4.dll!RpcServerRegisterIfEx 00007ff815e8fe20 6 bytes {JMP QWORD [RIP+0x350210]}
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1720] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1720] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1720] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1720] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1720] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[1720] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\System32\svchost.exe[1760] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\System32\svchost.exe[1760] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\System32\svchost.exe[1760] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\System32\svchost.exe[1760] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\System32\svchost.exe[1760] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\System32\svchost.exe[1760] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\system32\dashost.exe[1800] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\dashost.exe[1800] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\dashost.exe[1800] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156200d8
.text C:\WINDOWS\system32\dashost.exe[1800] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\system32\dashost.exe[1800] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\system32\dashost.exe[1800] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe[1808] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe[1808] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe[1808] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe[1808] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x5a6ce0]}
.text C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe[1808] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x5e5b10]}
.text C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe[1808] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x5a4080]}
.text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1868] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1868] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1868] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1868] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1868] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe[1868] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156200d8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0xb06ce0]}
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0xdd5b10]}
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0xc84080]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!MoveWindow 00007ff8162011d0 6 bytes {JMP QWORD [RIP+0x7aee60]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SetParent 00007ff816201220 4 bytes [FF, 25, 10, EE]
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SetParent + 5 00007ff816201225 1 byte [00]
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!GetKeyboardState 00007ff816201230 6 bytes {JMP QWORD [RIP+0x70ee00]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SendInput 00007ff816201240 6 bytes {JMP QWORD [RIP+0x6eedf0]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SetClipboardViewer 00007ff8162014e0 6 bytes {JMP QWORD [RIP+0x7ceb50]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!BlockInput 00007ff816201530 6 bytes {JMP QWORD [RIP+0x7eeb00]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!RegisterHotKey 00007ff816201c90 6 bytes {JMP QWORD [RIP+0x82e3a0]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!RegisterRawInputDevices 00007ff816201cb0 6 bytes {JMP QWORD [RIP+0x76e380]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!PostMessageW 00007ff8162033f0 6 bytes {JMP QWORD [RIP+0x3acc40]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!PostThreadMessageW 00007ff8162035a0 6 bytes {JMP QWORD [RIP+0x3eca90]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutW + 1 00007ff816204311 5 bytes {JMP QWORD [RIP+0x46bd20]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoW 00007ff8162054e0 6 bytes {JMP QWORD [RIP+0x86ab50]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SendMessageW 00007ff816205720 6 bytes {JMP QWORD [RIP+0x42a910]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackW 00007ff8162062b0 6 bytes {JMP QWORD [RIP+0x4a9d80]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW 00007ff816206390 6 bytes {JMP QWORD [RIP+0x309ca0]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SetWindowLongW 00007ff8162093d0 6 bytes {JMP QWORD [RIP+0x366c60]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!mouse_event 00007ff816209f00 6 bytes {JMP QWORD [RIP+0x2c6130]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW 00007ff81620b7f0 3 bytes [FF, 25, 40]
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW + 4 00007ff81620b7f4 2 bytes [68, 00]
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!GetKeyState + 1 00007ff81620fd81 5 bytes {JMP QWORD [RIP+0x7202b0]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoA 00007ff816213740 6 bytes {JMP QWORD [RIP+0x83c8f0]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SetWindowLongA 00007ff816213c60 5 bytes [FF, 25, D0, C3, 33]
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!EnableWindow 00007ff816214610 6 bytes {JMP QWORD [RIP+0x87ba20]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!GetAsyncKeyState 00007ff816214b80 6 bytes {JMP QWORD [RIP+0x73b4b0]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SetWinEventHook + 1 00007ff816217101 5 bytes {JMP QWORD [RIP+0x318f30]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!PostThreadMessageA 00007ff8162255b0 6 bytes {JMP QWORD [RIP+0x3aaa80]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!PostMessageA 00007ff816225920 6 bytes {JMP QWORD [RIP+0x36a710]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SendMessageA 00007ff816226190 6 bytes {JMP QWORD [RIP+0x3e9ea0]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!ExitWindowsEx 00007ff816234520 6 bytes {JMP QWORD [RIP+0x87bb10]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageW 00007ff816236480 6 bytes {JMP QWORD [RIP+0x699bb0]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageA 00007ff81623c620 6 bytes {JMP QWORD [RIP+0x633a10]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!GetClipboardData 00007ff81623efb0 6 bytes {JMP QWORD [RIP+0x7d1080]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutA 00007ff81623f600 6 bytes {JMP QWORD [RIP+0x410a30]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA 00007ff816260f60 6 bytes {JMP QWORD [RIP+0x28f0d0]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!keybd_event 00007ff816289620 6 bytes {JMP QWORD [RIP+0x226a10]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageA 00007ff816290f30 6 bytes {JMP QWORD [RIP+0x61f100]}
.text C:\WINDOWS\system32\svchost.exe[1452] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackA 00007ff8162918f0 6 bytes {JMP QWORD [RIP+0x3fe740]}
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2192] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2192] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2192] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156200d8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2192] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0xb06ce0]}
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2192] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0xdd5b10]}
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2192] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0xc84080]}
.text C:\WINDOWS\system32\svchost.exe[2300] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\svchost.exe[2300] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\svchost.exe[2300] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\system32\svchost.exe[2300] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\system32\svchost.exe[2300] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\system32\svchost.exe[2300] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\system32\conhost.exe[2308] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\conhost.exe[2308] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\conhost.exe[2308] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\system32\conhost.exe[2308] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x5a6ce0]}
.text C:\WINDOWS\system32\conhost.exe[2308] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x5e5b10]}
.text C:\WINDOWS\system32\conhost.exe[2308] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x5a4080]}
.text C:\WINDOWS\system32\svchost.exe[2388] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\svchost.exe[2388] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\svchost.exe[2388] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\system32\svchost.exe[2388] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\system32\svchost.exe[2388] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\system32\svchost.exe[2388] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x5a6ce0]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x5e5b10]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x5a4080]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!MoveWindow 00007ff8162011d0 6 bytes {JMP QWORD [RIP+0x7aee60]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SetParent 00007ff816201220 4 bytes [FF, 25, 10, EE]
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SetParent + 5 00007ff816201225 1 byte [00]
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!GetKeyboardState 00007ff816201230 6 bytes {JMP QWORD [RIP+0x70ee00]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SendInput 00007ff816201240 6 bytes {JMP QWORD [RIP+0x6eedf0]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SetClipboardViewer 00007ff8162014e0 6 bytes {JMP QWORD [RIP+0x7ceb50]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!BlockInput 00007ff816201530 6 bytes {JMP QWORD [RIP+0x7eeb00]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!RegisterHotKey 00007ff816201c90 6 bytes {JMP QWORD [RIP+0x82e3a0]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!RegisterRawInputDevices 00007ff816201cb0 6 bytes {JMP QWORD [RIP+0x76e380]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!PostMessageW 00007ff8162033f0 6 bytes {JMP QWORD [RIP+0x3acc40]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!PostThreadMessageW 00007ff8162035a0 6 bytes {JMP QWORD [RIP+0x3eca90]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutW + 1 00007ff816204311 5 bytes {JMP QWORD [RIP+0x46bd20]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoW 00007ff8162054e0 6 bytes {JMP QWORD [RIP+0x86ab50]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SendMessageW 00007ff816205720 6 bytes {JMP QWORD [RIP+0x42a910]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackW 00007ff8162062b0 6 bytes {JMP QWORD [RIP+0x4a9d80]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW 00007ff816206390 6 bytes {JMP QWORD [RIP+0x309ca0]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SetWindowLongW 00007ff8162093d0 6 bytes {JMP QWORD [RIP+0x366c60]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!mouse_event 00007ff816209f00 6 bytes {JMP QWORD [RIP+0x2c6130]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW 00007ff81620b7f0 3 bytes [FF, 25, 40]
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW + 4 00007ff81620b7f4 2 bytes [68, 00]
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!GetKeyState + 1 00007ff81620fd81 5 bytes {JMP QWORD [RIP+0x7202b0]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoA 00007ff816213740 6 bytes {JMP QWORD [RIP+0x83c8f0]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SetWindowLongA 00007ff816213c60 5 bytes [FF, 25, D0, C3, 33]
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!EnableWindow 00007ff816214610 6 bytes {JMP QWORD [RIP+0x87ba20]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!GetAsyncKeyState 00007ff816214b80 6 bytes {JMP QWORD [RIP+0x73b4b0]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SetWinEventHook + 1 00007ff816217101 5 bytes {JMP QWORD [RIP+0x318f30]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!PostThreadMessageA 00007ff8162255b0 6 bytes {JMP QWORD [RIP+0x3aaa80]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!PostMessageA 00007ff816225920 6 bytes {JMP QWORD [RIP+0x36a710]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SendMessageA 00007ff816226190 6 bytes {JMP QWORD [RIP+0x3e9ea0]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!ExitWindowsEx 00007ff816234520 6 bytes {JMP QWORD [RIP+0x87bb10]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageW 00007ff816236480 6 bytes {JMP QWORD [RIP+0x699bb0]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageA 00007ff81623c620 6 bytes {JMP QWORD [RIP+0x633a10]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!GetClipboardData 00007ff81623efb0 6 bytes {JMP QWORD [RIP+0x7d1080]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutA 00007ff81623f600 6 bytes {JMP QWORD [RIP+0x410a30]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA 00007ff816260f60 6 bytes {JMP QWORD [RIP+0x28f0d0]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!keybd_event 00007ff816289620 6 bytes {JMP QWORD [RIP+0x226a10]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageA 00007ff816290f30 6 bytes {JMP QWORD [RIP+0x61f100]}
.text C:\WINDOWS\system32\SearchIndexer.exe[3696] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackA 00007ff8162918f0 6 bytes {JMP QWORD [RIP+0x3fe740]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156200d8
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0xaf6ce0]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0xcb5b10]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0xaf4080]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!MoveWindow 00007ff8162011d0 6 bytes {JMP QWORD [RIP+0x84ee60]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SetParent 00007ff816201220 6 bytes {JMP QWORD [RIP+0x82ee10]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!GetKeyboardState 00007ff816201230 6 bytes {JMP QWORD [RIP+0x7aee00]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SendInput 00007ff816201240 6 bytes {JMP QWORD [RIP+0x78edf0]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SetClipboardViewer 00007ff8162014e0 6 bytes {JMP QWORD [RIP+0x86eb50]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!BlockInput 00007ff816201530 6 bytes {JMP QWORD [RIP+0x88eb00]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!RegisterHotKey 00007ff816201c90 6 bytes {JMP QWORD [RIP+0x8ce3a0]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!RegisterRawInputDevices 00007ff816201cb0 6 bytes {JMP QWORD [RIP+0x80e380]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!PostMessageW 00007ff8162033f0 6 bytes {JMP QWORD [RIP+0x44cc40]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!PostThreadMessageW 00007ff8162035a0 6 bytes {JMP QWORD [RIP+0x48ca90]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutW + 1 00007ff816204311 5 bytes {JMP QWORD [RIP+0x6abd20]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoW 00007ff8162054e0 6 bytes {JMP QWORD [RIP+0x90ab50]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SendMessageW 00007ff816205720 6 bytes {JMP QWORD [RIP+0x66a910]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackW 00007ff8162062b0 6 bytes {JMP QWORD [RIP+0x6e9d80]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW 00007ff816206390 6 bytes {JMP QWORD [RIP+0x3a9ca0]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SetWindowLongW 00007ff8162093d0 6 bytes {JMP QWORD [RIP+0x406c60]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!mouse_event 00007ff816209f00 6 bytes {JMP QWORD [RIP+0x366130]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW 00007ff81620b7f0 3 bytes [FF, 25, 40]
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW + 4 00007ff81620b7f4 2 bytes [72, 00]
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!GetKeyState + 1 00007ff81620fd81 5 bytes {JMP QWORD [RIP+0x7c02b0]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoA 00007ff816213740 6 bytes {JMP QWORD [RIP+0x8dc8f0]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SetWindowLongA 00007ff816213c60 5 bytes [FF, 25, D0, C3, 3D]
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!EnableWindow 00007ff816214610 6 bytes {JMP QWORD [RIP+0x91ba20]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!GetAsyncKeyState 00007ff816214b80 6 bytes {JMP QWORD [RIP+0x7db4b0]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SetWinEventHook + 1 00007ff816217101 5 bytes {JMP QWORD [RIP+0x3b8f30]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!PostThreadMessageA 00007ff8162255b0 6 bytes {JMP QWORD [RIP+0x44aa80]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!PostMessageA 00007ff816225920 6 bytes {JMP QWORD [RIP+0x40a710]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SendMessageA 00007ff816226190 6 bytes {JMP QWORD [RIP+0x489ea0]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!ExitWindowsEx 00007ff816234520 6 bytes {JMP QWORD [RIP+0x91bb10]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageW 00007ff816236480 6 bytes {JMP QWORD [RIP+0x739bb0]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageA 00007ff81623c620 6 bytes {JMP QWORD [RIP+0x6d3a10]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!GetClipboardData 00007ff81623efb0 6 bytes {JMP QWORD [RIP+0x871080]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutA 00007ff81623f600 6 bytes {JMP QWORD [RIP+0x650a30]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA 00007ff816260f60 6 bytes {JMP QWORD [RIP+0x32f0d0]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!keybd_event 00007ff816289620 6 bytes {JMP QWORD [RIP+0x2c6a10]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageA 00007ff816290f30 6 bytes {JMP QWORD [RIP+0x6bf100]}
.text C:\Program Files\iPod\bin\iPodService.exe[2224] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackA 00007ff8162918f0 6 bytes {JMP QWORD [RIP+0x63e740]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x336ce0]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x375b10]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x334080]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!MoveWindow 00007ff8162011d0 6 bytes {JMP QWORD [RIP+0x7aee60]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SetParent 00007ff816201220 4 bytes [FF, 25, 10, EE]
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SetParent + 5 00007ff816201225 1 byte [00]
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!GetKeyboardState 00007ff816201230 6 bytes {JMP QWORD [RIP+0x70ee00]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SendInput 00007ff816201240 6 bytes {JMP QWORD [RIP+0x6eedf0]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SetClipboardViewer 00007ff8162014e0 6 bytes {JMP QWORD [RIP+0x7ceb50]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!BlockInput 00007ff816201530 6 bytes {JMP QWORD [RIP+0x7eeb00]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!RegisterHotKey 00007ff816201c90 6 bytes {JMP QWORD [RIP+0x82e3a0]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!RegisterRawInputDevices 00007ff816201cb0 6 bytes {JMP QWORD [RIP+0x76e380]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!PostMessageW 00007ff8162033f0 6 bytes {JMP QWORD [RIP+0x3acc40]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!PostThreadMessageW 00007ff8162035a0 6 bytes {JMP QWORD [RIP+0x3eca90]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutW + 1 00007ff816204311 5 bytes {JMP QWORD [RIP+0x46bd20]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoW 00007ff8162054e0 6 bytes {JMP QWORD [RIP+0x86ab50]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SendMessageW 00007ff816205720 6 bytes {JMP QWORD [RIP+0x42a910]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackW 00007ff8162062b0 6 bytes {JMP QWORD [RIP+0x4a9d80]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW 00007ff816206390 6 bytes {JMP QWORD [RIP+0x309ca0]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SetWindowLongW 00007ff8162093d0 6 bytes {JMP QWORD [RIP+0x366c60]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!mouse_event 00007ff816209f00 6 bytes {JMP QWORD [RIP+0x2c6130]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW 00007ff81620b7f0 3 bytes [FF, 25, 40]
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW + 4 00007ff81620b7f4 2 bytes [68, 00]
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!GetKeyState + 1 00007ff81620fd81 5 bytes {JMP QWORD [RIP+0x7202b0]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoA 00007ff816213740 6 bytes {JMP QWORD [RIP+0x83c8f0]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SetWindowLongA 00007ff816213c60 5 bytes [FF, 25, D0, C3, 33]
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!EnableWindow 00007ff816214610 6 bytes {JMP QWORD [RIP+0x87ba20]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!GetAsyncKeyState 00007ff816214b80 6 bytes {JMP QWORD [RIP+0x73b4b0]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SetWinEventHook + 1 00007ff816217101 5 bytes {JMP QWORD [RIP+0x318f30]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!PostThreadMessageA 00007ff8162255b0 6 bytes {JMP QWORD [RIP+0x3aaa80]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!PostMessageA 00007ff816225920 6 bytes {JMP QWORD [RIP+0x36a710]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SendMessageA 00007ff816226190 6 bytes {JMP QWORD [RIP+0x3e9ea0]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!ExitWindowsEx 00007ff816234520 6 bytes {JMP QWORD [RIP+0x87bb10]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageW 00007ff816236480 6 bytes {JMP QWORD [RIP+0x699bb0]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageA 00007ff81623c620 6 bytes {JMP QWORD [RIP+0x633a10]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!GetClipboardData 00007ff81623efb0 6 bytes {JMP QWORD [RIP+0x7d1080]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutA 00007ff81623f600 6 bytes {JMP QWORD [RIP+0x410a30]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA 00007ff816260f60 6 bytes {JMP QWORD [RIP+0x28f0d0]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!keybd_event 00007ff816289620 6 bytes {JMP QWORD [RIP+0x226a10]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageA 00007ff816290f30 6 bytes {JMP QWORD [RIP+0x61f100]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackA 00007ff8162918f0 6 bytes {JMP QWORD [RIP+0x3fe740]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\GDI32.dll!BitBlt 00007ff815823d80 6 bytes {JMP QWORD [RIP+0x3fc2b0]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\GDI32.dll!CreateDCW 00007ff815834a00 6 bytes {JMP QWORD [RIP+0x18b630]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\GDI32.dll!CreateDCA 00007ff815834b70 6 bytes {JMP QWORD [RIP+0x16b4c0]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\GDI32.dll!MaskBlt 00007ff815837d30 6 bytes {JMP QWORD [RIP+0x408300]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\GDI32.dll!StretchBlt 00007ff815842e30 6 bytes {JMP QWORD [RIP+0x43d200]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\GDI32.dll!GetPixel 00007ff815842f40 6 bytes {JMP QWORD [RIP+0x19d0f0]}
.text C:\WINDOWS\System32\dwm.exe[8520] C:\WINDOWS\system32\GDI32.dll!PlgBlt 00007ff8158a3f30 6 bytes {JMP QWORD [RIP+0x3bc100]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156700d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0x5a6ce0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes {JMP QWORD [RIP+0x5e5b10]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\KERNELBASE.dll!CopyFile2 00007ff8156fbfb0 6 bytes {JMP QWORD [RIP+0x5a4080]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!MoveWindow 00007ff8162011d0 6 bytes {JMP QWORD [RIP+0x7aee60]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SetParent 00007ff816201220 4 bytes [FF, 25, 10, EE]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SetParent + 5 00007ff816201225 1 byte [00]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!GetKeyboardState 00007ff816201230 6 bytes {JMP QWORD [RIP+0x70ee00]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SendInput 00007ff816201240 6 bytes {JMP QWORD [RIP+0x6eedf0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SetClipboardViewer 00007ff8162014e0 6 bytes {JMP QWORD [RIP+0x7ceb50]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!BlockInput 00007ff816201530 6 bytes {JMP QWORD [RIP+0x7eeb00]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!RegisterHotKey 00007ff816201c90 6 bytes {JMP QWORD [RIP+0x82e3a0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!RegisterRawInputDevices 00007ff816201cb0 6 bytes {JMP QWORD [RIP+0x76e380]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!PostMessageW 00007ff8162033f0 6 bytes {JMP QWORD [RIP+0x3acc40]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!PostThreadMessageW 00007ff8162035a0 6 bytes {JMP QWORD [RIP+0x3eca90]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutW + 1 00007ff816204311 5 bytes {JMP QWORD [RIP+0x46bd20]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoW 00007ff8162054e0 6 bytes {JMP QWORD [RIP+0x86ab50]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SendMessageW 00007ff816205720 6 bytes {JMP QWORD [RIP+0x42a910]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackW 00007ff8162062b0 6 bytes {JMP QWORD [RIP+0x4a9d80]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExW 00007ff816206390 6 bytes {JMP QWORD [RIP+0x309ca0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SetWindowLongW 00007ff8162093d0 6 bytes {JMP QWORD [RIP+0x366c60]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!mouse_event 00007ff816209f00 6 bytes {JMP QWORD [RIP+0x2c6130]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW 00007ff81620b7f0 3 bytes [FF, 25, 40]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageW + 4 00007ff81620b7f4 2 bytes [68, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!GetKeyState + 1 00007ff81620fd81 5 bytes {JMP QWORD [RIP+0x7202b0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SystemParametersInfoA 00007ff816213740 6 bytes {JMP QWORD [RIP+0x83c8f0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SetWindowLongA 00007ff816213c60 5 bytes [FF, 25, D0, C3, 33]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!EnableWindow 00007ff816214610 6 bytes {JMP QWORD [RIP+0x87ba20]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!GetAsyncKeyState 00007ff816214b80 6 bytes {JMP QWORD [RIP+0x73b4b0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SetWinEventHook + 1 00007ff816217101 5 bytes {JMP QWORD [RIP+0x318f30]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!PostThreadMessageA 00007ff8162255b0 6 bytes {JMP QWORD [RIP+0x3aaa80]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!PostMessageA 00007ff816225920 6 bytes {JMP QWORD [RIP+0x36a710]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SendMessageA 00007ff816226190 6 bytes {JMP QWORD [RIP+0x3e9ea0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!ExitWindowsEx 00007ff816234520 6 bytes {JMP QWORD [RIP+0x87bb10]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageW 00007ff816236480 6 bytes {JMP QWORD [RIP+0x699bb0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SendNotifyMessageA 00007ff81623c620 6 bytes {JMP QWORD [RIP+0x633a10]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!GetClipboardData 00007ff81623efb0 6 bytes {JMP QWORD [RIP+0x7d1080]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SendMessageTimeoutA 00007ff81623f600 6 bytes {JMP QWORD [RIP+0x410a30]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SetWindowsHookExA 00007ff816260f60 6 bytes {JMP QWORD [RIP+0x28f0d0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!keybd_event 00007ff816289620 6 bytes {JMP QWORD [RIP+0x226a10]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SendDlgItemMessageA 00007ff816290f30 6 bytes {JMP QWORD [RIP+0x61f100]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\USER32.dll!SendMessageCallbackA 00007ff8162918f0 6 bytes {JMP QWORD [RIP+0x3fe740]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\GDI32.dll!BitBlt 00007ff815823d80 6 bytes {JMP QWORD [RIP+0x4cc2b0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\GDI32.dll!CreateDCW 00007ff815834a00 6 bytes {JMP QWORD [RIP+0x3fb630]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\GDI32.dll!CreateDCA 00007ff815834b70 6 bytes {JMP QWORD [RIP+0x3db4c0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\GDI32.dll!MaskBlt 00007ff815837d30 6 bytes {JMP QWORD [RIP+0x4d8300]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\GDI32.dll!StretchBlt 00007ff815842e30 6 bytes {JMP QWORD [RIP+0x50d200]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\GDI32.dll!GetPixel 00007ff815842f40 6 bytes {JMP QWORD [RIP+0x40d0f0]}
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[7440] C:\WINDOWS\system32\GDI32.dll!PlgBlt 00007ff8158a3f30 6 bytes {JMP QWORD [RIP+0x48c100]}
.text C:\WINDOWS\system32\nvvsvc.exe[8424] C:\WINDOWS\system32\KERNELBASE.dll!LoadLibraryExW + 198 00007ff815688e46 3 bytes [C4, 71, 11]
.text C:\WINDOWS\system32\nvvsvc.exe[8424] C:\WINDOWS\system32\KERNELBASE.dll!SetProcessShutdownParameters 00007ff815698ca0 5 bytes [FF, 25, 90, 73, 15]
.text C:\WINDOWS\system32\nvvsvc.exe[8424] C:\WINDOWS\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff81569ef70 5 bytes JMP 00007ff9156200d8
.text C:\WINDOWS\system32\nvvsvc.exe[8424] C:\WINDOWS\system32\KERNELBASE.dll!MoveFileWithProgressTransactedW + 1 00007ff8156d9351 5 bytes {JMP QWORD [RIP+0xcb6ce0]}
.text C:\WINDOWS\system32\nvvsvc.exe[8424] C:\WINDOWS\system32\KERNELBASE.dll!CopyFileExW 00007ff8156da520 6 bytes JMP 0 |