RobinSword | 05.03.2013 13:19 | Hier schon mal das GMER-Log: Code:
GMER 2.1.19155 - hxxp://www.gmer.net
Rootkit scan 2013-03-05 13:18:41
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk1\DR1 -> \Device\00000073 ATA_____ rev.1___ 238,47GB
Running: gmer_2.1.19155.exe; Driver: C:\Users\Robert\AppData\Local\Temp\awloqpog.sys
---- User code sections - GMER 2.1 ----
.text C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe[1712] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076c01465 2 bytes [C0, 76]
.text C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe[1712] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076c014bb 2 bytes [C0, 76]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000777c08fc 4 bytes [68, A0, CF, 41]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 00000000777c0901 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000777d25fd 6 bytes [68, BD, 57, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 00000000777dc45a 6 bytes [68, CB, D0, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 00000000777e2a63 6 bytes [68, 03, 58, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077804128 6 bytes [68, 49, 58, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007780e659 6 bytes [68, 8F, 58, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 00000000767d455c 6 bytes [68, 34, D3, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000767d79f8 6 bytes [68, F3, D2, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!GetDC 00000000761c72c4 4 bytes [68, 92, 18, 41]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000761c72c9 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000761c7446 6 bytes [68, 10, 19, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000761c7809 6 bytes [68, A5, 5D, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000761c78e2 6 bytes [68, 22, DE, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000761c7bd3 6 bytes [68, 4A, DE, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000761c8048 4 bytes [68, D1, 18, 41]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000761c804d 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000761c8a65 6 bytes [68, C1, 5A, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000761cb17d 6 bytes [68, 5B, 5B, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000761cdb98 6 bytes [68, AD, 5B, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000761d05ba 6 bytes [68, 72, DE, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000761d0d32 6 bytes [68, F3, 59, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000761d1218 6 bytes [68, 55, DC, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!EndPaint 00000000761d1341 4 bytes [68, F7, 17, 41]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!EndPaint + 5 00000000761d1346 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000761d1361 4 bytes [68, 87, 17, 41]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 00000000761d1366 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000761d2a8d 6 bytes [68, 23, DC, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!GetCapture 00000000761d2aac 6 bytes [68, 83, DD, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000761d3391 4 bytes [68, 37, 18, 41]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 00000000761d3396 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000761d434b 6 bytes [68, 0E, 5B, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000761d5f74 6 bytes [68, 9D, DE, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000761d6222 6 bytes [68, E3, 19, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000761d792f 6 bytes [68, 3C, 5A, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000761d7fbb 6 bytes [68, 1E, 59, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000761d810c 6 bytes [68, AD, 59, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000761d85c1 6 bytes [68, D5, 58, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000761d86b4 6 bytes [68, 67, 59, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!GetUpdateRect 00000000761ed41f 6 bytes [68, 50, 19, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!ReleaseCapture 00000000761eed49 6 bytes [68, 33, DD, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!SetCapture 00000000761eed56 4 bytes [68, D9, DC, 41]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!SetCapture + 5 00000000761eed5b 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000076209854 6 bytes [68, 9F, 57, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000076209cfd 6 bytes [68, 9C, DC, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000076209f1d 6 bytes [68, 54, 5F, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000762287cb 4 bytes [68, 4F, 57, 42]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 00000000762287d0 1 byte [C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 0000000076b5c592 6 bytes [68, B1, D3, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000076b92538 6 bytes [68, 9A, D3, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000074f71224 6 bytes [68, 89, 7E, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WS2_32.dll!closesocket 00000000765b3918 6 bytes [68, 27, E3, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 00000000765b4296 6 bytes [68, 38, DF, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WS2_32.dll!WSASend 00000000765b4406 6 bytes [68, 80, E3, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WS2_32.dll!send 00000000765b6f01 6 bytes [68, 5F, E3, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WS2_32.dll!gethostbyname 00000000765c7673 6 bytes [68, C8, DE, 41, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000076c1c664 6 bytes [68, DC, 08, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000076c1e13a 6 bytes [68, 7C, 0A, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000076c1f8d8 6 bytes [68, 49, 09, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000076c23184 6 bytes [68, 50, 0A, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000076c45761 6 bytes [68, 1E, 06, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000076c45fef 6 bytes [68, DA, 05, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000076c4632d 6 bytes [68, 62, 06, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000076c4fa49 6 bytes [68, 77, 09, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076c5f564 6 bytes [68, 0C, 07, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000076c5f639 6 bytes [68, 46, 08, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000076c74f2f 6 bytes [68, F6, 09, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076c7525a 6 bytes [68, B7, 06, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000076cbece5 6 bytes [68, A9, 07, 42, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[2396] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000076cbedb7 6 bytes [68, 91, 08, 42, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000777c08fc 4 bytes [68, A0, CF, EE]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 00000000777c0901 1 byte [C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000777d25fd 6 bytes [68, BD, 57, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 00000000777dc45a 6 bytes [68, CB, D0, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 00000000777e2a63 6 bytes [68, 03, 58, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077804128 6 bytes [68, 49, 58, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007780e659 6 bytes [68, 8F, 58, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 00000000767d455c 6 bytes [68, 34, D3, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000767d79f8 6 bytes [68, F3, D2, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 0000000076b5c592 6 bytes [68, B1, D3, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000076b92538 6 bytes [68, 9A, D3, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!GetDC 00000000761c72c4 4 bytes [68, 92, 18, EE]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000761c72c9 1 byte [C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000761c7446 6 bytes [68, 10, 19, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000761c7809 6 bytes [68, A5, 5D, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000761c78e2 6 bytes [68, 22, DE, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000761c7bd3 6 bytes [68, 4A, DE, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000761c8048 4 bytes [68, D1, 18, EE]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000761c804d 1 byte [C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000761c8a65 6 bytes [68, C1, 5A, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000761cb17d 6 bytes [68, 5B, 5B, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000761cdb98 6 bytes [68, AD, 5B, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000761d05ba 6 bytes [68, 72, DE, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000761d0d32 6 bytes [68, F3, 59, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000761d1218 6 bytes [68, 55, DC, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!EndPaint 00000000761d1341 4 bytes [68, F7, 17, EE]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!EndPaint + 5 00000000761d1346 1 byte [C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000761d1361 4 bytes [68, 87, 17, EE]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 00000000761d1366 1 byte [C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000761d2a8d 6 bytes [68, 23, DC, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!GetCapture 00000000761d2aac 6 bytes [68, 83, DD, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000761d3391 4 bytes [68, 37, 18, EE]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 00000000761d3396 1 byte [C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000761d434b 6 bytes [68, 0E, 5B, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000761d5f74 6 bytes [68, 9D, DE, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000761d6222 6 bytes [68, E3, 19, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000761d792f 6 bytes [68, 3C, 5A, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000761d7fbb 6 bytes [68, 1E, 59, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000761d810c 6 bytes [68, AD, 59, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000761d85c1 6 bytes [68, D5, 58, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000761d86b4 6 bytes [68, 67, 59, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!GetUpdateRect 00000000761ed41f 6 bytes [68, 50, 19, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!ReleaseCapture 00000000761eed49 6 bytes [68, 33, DD, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!SetCapture 00000000761eed56 4 bytes [68, D9, DC, EE]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!SetCapture + 5 00000000761eed5b 1 byte [C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000076209854 6 bytes [68, 9F, 57, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000076209cfd 6 bytes [68, 9C, DC, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000076209f1d 6 bytes [68, 54, 5F, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000762287cb 4 bytes [68, 4F, 57, EF]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 00000000762287d0 1 byte [C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WS2_32.dll!closesocket 00000000765b3918 6 bytes [68, 27, E3, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 00000000765b4296 6 bytes [68, 38, DF, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WS2_32.dll!WSASend 00000000765b4406 6 bytes [68, 80, E3, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WS2_32.dll!send 00000000765b6f01 6 bytes [68, 5F, E3, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WS2_32.dll!gethostbyname 00000000765c7673 6 bytes [68, C8, DE, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000074f71224 6 bytes [68, 89, 7E, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000076c1c664 6 bytes [68, DC, 08, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000076c1e13a 6 bytes [68, 7C, 0A, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000076c1f8d8 6 bytes [68, 49, 09, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000076c23184 6 bytes [68, 50, 0A, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000076c45761 6 bytes [68, 1E, 06, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000076c45fef 6 bytes [68, DA, 05, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000076c4632d 6 bytes [68, 62, 06, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000076c4fa49 6 bytes [68, 77, 09, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076c5f564 6 bytes [68, 0C, 07, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000076c5f639 6 bytes [68, 46, 08, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000076c74f2f 6 bytes [68, F6, 09, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076c7525a 6 bytes [68, B7, 06, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000076cbece5 6 bytes [68, A9, 07, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000076cbedb7 6 bytes [68, 91, 08, EF, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\SysWOW64\WINMM.dll!PlaySoundW 0000000074bd2ef2 6 bytes [68, EF, D3, EE, 00, C3]
.text C:\Windows\SysWOW64\Ctxfihlp.exe[2420] C:\Windows\SysWOW64\WINMM.dll!PlaySound 0000000074bf441d 6 bytes [68, C8, D3, EE, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076c01465 2 bytes [C0, 76]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2500] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076c014bb 2 bytes [C0, 76]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000777c08fc 4 bytes [68, A0, CF, 2B]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 00000000777c0901 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000777d25fd 6 bytes [68, BD, 57, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 00000000777dc45a 6 bytes [68, CB, D0, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 00000000777e2a63 6 bytes [68, 03, 58, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077804128 6 bytes [68, 49, 58, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007780e659 6 bytes [68, 8F, 58, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 00000000767d455c 6 bytes [68, 34, D3, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000767d79f8 6 bytes [68, F3, D2, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 0000000076b5c592 6 bytes [68, B1, D3, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000076b92538 6 bytes [68, 9A, D3, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!GetDC 00000000761c72c4 4 bytes [68, 92, 18, 2B]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000761c72c9 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000761c7446 6 bytes [68, 10, 19, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000761c7809 6 bytes [68, A5, 5D, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000761c78e2 6 bytes [68, 22, DE, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000761c7bd3 6 bytes [68, 4A, DE, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000761c8048 4 bytes [68, D1, 18, 2B]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000761c804d 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000761c8a65 6 bytes [68, C1, 5A, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000761cb17d 6 bytes [68, 5B, 5B, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000761cdb98 6 bytes [68, AD, 5B, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000761d05ba 6 bytes [68, 72, DE, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000761d0d32 6 bytes [68, F3, 59, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000761d1218 6 bytes [68, 55, DC, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!EndPaint 00000000761d1341 4 bytes [68, F7, 17, 2B]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!EndPaint + 5 00000000761d1346 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000761d1361 4 bytes [68, 87, 17, 2B]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 00000000761d1366 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000761d2a8d 6 bytes [68, 23, DC, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!GetCapture 00000000761d2aac 6 bytes [68, 83, DD, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000761d3391 4 bytes [68, 37, 18, 2B]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 00000000761d3396 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000761d434b 6 bytes [68, 0E, 5B, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000761d5f74 6 bytes [68, 9D, DE, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000761d6222 6 bytes [68, E3, 19, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000761d792f 6 bytes [68, 3C, 5A, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000761d7fbb 6 bytes [68, 1E, 59, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000761d810c 6 bytes [68, AD, 59, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000761d85c1 6 bytes [68, D5, 58, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000761d86b4 6 bytes [68, 67, 59, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!GetUpdateRect 00000000761ed41f 6 bytes [68, 50, 19, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!ReleaseCapture 00000000761eed49 6 bytes [68, 33, DD, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!SetCapture 00000000761eed56 4 bytes [68, D9, DC, 2B]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!SetCapture + 5 00000000761eed5b 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000076209854 6 bytes [68, 9F, 57, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000076209cfd 6 bytes [68, 9C, DC, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000076209f1d 6 bytes [68, 54, 5F, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000762287cb 4 bytes [68, 4F, 57, 2C]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 00000000762287d0 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000074f71224 6 bytes [68, 89, 7E, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076c01465 2 bytes [C0, 76]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076c014bb 2 bytes [C0, 76]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WS2_32.dll!closesocket 00000000765b3918 6 bytes [68, 27, E3, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 00000000765b4296 6 bytes [68, 38, DF, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WS2_32.dll!WSASend 00000000765b4406 6 bytes [68, 80, E3, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WS2_32.dll!send 00000000765b6f01 6 bytes [68, 5F, E3, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WS2_32.dll!gethostbyname 00000000765c7673 6 bytes [68, C8, DE, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000076c1c664 6 bytes [68, DC, 08, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000076c1e13a 6 bytes [68, 7C, 0A, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000076c1f8d8 6 bytes [68, 49, 09, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000076c23184 6 bytes [68, 50, 0A, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000076c45761 6 bytes [68, 1E, 06, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000076c45fef 6 bytes [68, DA, 05, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000076c4632d 6 bytes [68, 62, 06, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000076c4fa49 6 bytes [68, 77, 09, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076c5f564 6 bytes [68, 0C, 07, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000076c5f639 6 bytes [68, 46, 08, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000076c74f2f 6 bytes [68, F6, 09, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076c7525a 6 bytes [68, B7, 06, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000076cbece5 6 bytes [68, A9, 07, 2C, 00, C3]
.text C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe[2648] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000076cbedb7 6 bytes [68, 91, 08, 2C, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000777c08fc 4 bytes [68, A0, CF, 06]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 00000000777c0901 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000777d25fd 6 bytes [68, BD, 57, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 00000000777dc45a 6 bytes [68, CB, D0, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 00000000777e2a63 6 bytes [68, 03, 58, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077804128 6 bytes [68, 49, 58, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007780e659 6 bytes [68, 8F, 58, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 00000000767d455c 6 bytes [68, 34, D3, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000767d79f8 6 bytes [68, F3, D2, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 0000000076b5c592 6 bytes [68, B1, D3, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000076b92538 6 bytes [68, 9A, D3, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!GetDC 00000000761c72c4 4 bytes [68, 92, 18, 06]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000761c72c9 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000761c7446 6 bytes [68, 10, 19, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000761c7809 6 bytes [68, A5, 5D, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000761c78e2 6 bytes [68, 22, DE, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000761c7bd3 6 bytes [68, 4A, DE, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000761c8048 4 bytes [68, D1, 18, 06]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000761c804d 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000761c8a65 6 bytes [68, C1, 5A, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000761cb17d 6 bytes [68, 5B, 5B, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000761cdb98 6 bytes [68, AD, 5B, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000761d05ba 6 bytes [68, 72, DE, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000761d0d32 6 bytes [68, F3, 59, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000761d1218 6 bytes [68, 55, DC, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!EndPaint 00000000761d1341 4 bytes [68, F7, 17, 06]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!EndPaint + 5 00000000761d1346 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000761d1361 4 bytes [68, 87, 17, 06]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 00000000761d1366 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000761d2a8d 6 bytes [68, 23, DC, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!GetCapture 00000000761d2aac 6 bytes [68, 83, DD, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000761d3391 4 bytes [68, 37, 18, 06]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 00000000761d3396 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000761d434b 6 bytes [68, 0E, 5B, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000761d5f74 6 bytes [68, 9D, DE, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000761d6222 6 bytes [68, E3, 19, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000761d792f 6 bytes [68, 3C, 5A, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000761d7fbb 6 bytes [68, 1E, 59, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000761d810c 6 bytes [68, AD, 59, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000761d85c1 6 bytes [68, D5, 58, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000761d86b4 6 bytes [68, 67, 59, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!GetUpdateRect 00000000761ed41f 6 bytes [68, 50, 19, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!ReleaseCapture 00000000761eed49 6 bytes [68, 33, DD, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!SetCapture 00000000761eed56 4 bytes [68, D9, DC, 06]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!SetCapture + 5 00000000761eed5b 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000076209854 6 bytes [68, 9F, 57, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000076209cfd 6 bytes [68, 9C, DC, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000076209f1d 6 bytes [68, 54, 5F, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000762287cb 4 bytes [68, 4F, 57, 07]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 00000000762287d0 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WS2_32.dll!closesocket 00000000765b3918 6 bytes [68, 27, E3, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 00000000765b4296 6 bytes [68, 38, DF, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WS2_32.dll!WSASend 00000000765b4406 6 bytes [68, 80, E3, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WS2_32.dll!send 00000000765b6f01 6 bytes [68, 5F, E3, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WS2_32.dll!gethostbyname 00000000765c7673 6 bytes [68, C8, DE, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000074f71224 6 bytes [68, 89, 7E, 06, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000076c1c664 6 bytes [68, DC, 08, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000076c1e13a 6 bytes [68, 7C, 0A, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000076c1f8d8 6 bytes [68, 49, 09, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000076c23184 6 bytes [68, 50, 0A, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000076c45761 6 bytes [68, 1E, 06, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000076c45fef 6 bytes [68, DA, 05, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000076c4632d 6 bytes [68, 62, 06, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000076c4fa49 6 bytes [68, 77, 09, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076c5f564 6 bytes [68, 0C, 07, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000076c5f639 6 bytes [68, 46, 08, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000076c74f2f 6 bytes [68, F6, 09, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076c7525a 6 bytes [68, B7, 06, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000076cbece5 6 bytes [68, A9, 07, 07, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[2920] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000076cbedb7 6 bytes [68, 91, 08, 07, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000777c08fc 4 bytes [68, A0, CF, 1A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 00000000777c0901 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000777d25fd 6 bytes [68, BD, 57, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 00000000777dc45a 6 bytes [68, CB, D0, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 00000000777e2a63 6 bytes [68, 03, 58, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077804128 6 bytes [68, 49, 58, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007780e659 6 bytes [68, 8F, 58, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 00000000767d455c 6 bytes [68, 34, D3, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000767d79f8 6 bytes [68, F3, D2, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 0000000076b5c592 6 bytes [68, B1, D3, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000076b92538 6 bytes [68, 9A, D3, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!GetDC 00000000761c72c4 4 bytes [68, 92, 18, 1A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000761c72c9 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000761c7446 6 bytes [68, 10, 19, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000761c7809 6 bytes [68, A5, 5D, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000761c78e2 6 bytes [68, 22, DE, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000761c7bd3 6 bytes [68, 4A, DE, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000761c8048 4 bytes [68, D1, 18, 1A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000761c804d 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000761c8a65 6 bytes [68, C1, 5A, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000761cb17d 6 bytes [68, 5B, 5B, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000761cdb98 6 bytes [68, AD, 5B, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000761d05ba 6 bytes [68, 72, DE, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000761d0d32 6 bytes [68, F3, 59, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000761d1218 6 bytes [68, 55, DC, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!EndPaint 00000000761d1341 4 bytes [68, F7, 17, 1A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!EndPaint + 5 00000000761d1346 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000761d1361 4 bytes [68, 87, 17, 1A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 00000000761d1366 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000761d2a8d 6 bytes [68, 23, DC, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!GetCapture 00000000761d2aac 6 bytes [68, 83, DD, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000761d3391 4 bytes [68, 37, 18, 1A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 00000000761d3396 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000761d434b 6 bytes [68, 0E, 5B, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000761d5f74 6 bytes [68, 9D, DE, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000761d6222 6 bytes [68, E3, 19, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000761d792f 6 bytes [68, 3C, 5A, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000761d7fbb 6 bytes [68, 1E, 59, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000761d810c 6 bytes [68, AD, 59, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000761d85c1 6 bytes [68, D5, 58, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000761d86b4 6 bytes [68, 67, 59, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!GetUpdateRect 00000000761ed41f 6 bytes [68, 50, 19, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!ReleaseCapture 00000000761eed49 6 bytes [68, 33, DD, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!SetCapture 00000000761eed56 4 bytes [68, D9, DC, 1A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!SetCapture + 5 00000000761eed5b 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000076209854 6 bytes [68, 9F, 57, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000076209cfd 6 bytes [68, 9C, DC, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000076209f1d 6 bytes [68, 54, 5F, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000762287cb 4 bytes [68, 4F, 57, 1B]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 00000000762287d0 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000076c1c664 6 bytes [68, DC, 08, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000076c1e13a 6 bytes [68, 7C, 0A, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000076c1f8d8 6 bytes [68, 49, 09, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000076c23184 6 bytes [68, 50, 0A, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000076c45761 6 bytes [68, 1E, 06, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000076c45fef 6 bytes [68, DA, 05, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000076c4632d 6 bytes [68, 62, 06, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000076c4fa49 6 bytes [68, 77, 09, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076c5f564 6 bytes [68, 0C, 07, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000076c5f639 6 bytes [68, 46, 08, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000076c74f2f 6 bytes [68, F6, 09, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076c7525a 6 bytes [68, B7, 06, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000076cbece5 6 bytes [68, A9, 07, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000076cbedb7 6 bytes [68, 91, 08, 1B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WS2_32.dll!closesocket 00000000765b3918 6 bytes [68, 27, E3, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 00000000765b4296 6 bytes [68, 38, DF, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WS2_32.dll!WSASend 00000000765b4406 6 bytes [68, 80, E3, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WS2_32.dll!send 00000000765b6f01 6 bytes [68, 5F, E3, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\WS2_32.dll!gethostbyname 00000000765c7673 6 bytes [68, C8, DE, 1A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3028] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000074f71224 6 bytes [68, 89, 7E, 1A, 00, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000777c08fc 6 bytes [68, A0, CF, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000777d25fd 6 bytes [68, BD, 57, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 00000000777dc45a 6 bytes [68, CB, D0, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 00000000777e2a63 6 bytes [68, 03, 58, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077804128 6 bytes [68, 49, 58, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007780e659 6 bytes [68, 8F, 58, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 00000000767d455c 6 bytes [68, 34, D3, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000767d79f8 6 bytes [68, F3, D2, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 0000000076b5c592 6 bytes [68, B1, D3, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 0000000076b92538 6 bytes [68, 9A, D3, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!GetDC 00000000761c72c4 6 bytes [68, 92, 18, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000761c7446 6 bytes [68, 10, 19, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000761c7809 6 bytes [68, A5, 5D, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000761c78e2 6 bytes [68, 22, DE, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000761c7bd3 6 bytes [68, 4A, DE, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000761c8048 6 bytes [68, D1, 18, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000761c8a65 6 bytes [68, C1, 5A, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000761cb17d 6 bytes [68, 5B, 5B, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000761cdb98 6 bytes [68, AD, 5B, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000761d05ba 6 bytes [68, 72, DE, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000761d0d32 6 bytes [68, F3, 59, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000761d1218 6 bytes [68, 55, DC, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!EndPaint 00000000761d1341 6 bytes [68, F7, 17, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000761d1361 6 bytes [68, 87, 17, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000761d2a8d 6 bytes [68, 23, DC, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!GetCapture 00000000761d2aac 6 bytes [68, 83, DD, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000761d3391 6 bytes [68, 37, 18, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000761d434b 6 bytes [68, 0E, 5B, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000761d5f74 6 bytes [68, 9D, DE, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000761d6222 6 bytes [68, E3, 19, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000761d792f 6 bytes [68, 3C, 5A, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000761d7fbb 6 bytes [68, 1E, 59, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000761d810c 6 bytes [68, AD, 59, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000761d85c1 6 bytes [68, D5, 58, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000761d86b4 6 bytes [68, 67, 59, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!GetUpdateRect 00000000761ed41f 6 bytes [68, 50, 19, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!ReleaseCapture 00000000761eed49 6 bytes [68, 33, DD, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!SetCapture 00000000761eed56 6 bytes [68, D9, DC, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000076209854 6 bytes [68, 9F, 57, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000076209cfd 6 bytes [68, 9C, DC, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000076209f1d 6 bytes [68, 54, 5F, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000762287cb 6 bytes [68, 4F, 57, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\SysWOW64\WINMM.dll!PlaySoundW 0000000074bd2ef2 6 bytes [68, EF, D3, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\SysWOW64\WINMM.dll!PlaySound 0000000074bf441d 6 bytes [68, C8, D3, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000074f71224 6 bytes [68, 89, 7E, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WS2_32.dll!closesocket 00000000765b3918 6 bytes [68, 27, E3, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 00000000765b4296 6 bytes [68, 38, DF, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WS2_32.dll!WSASend 00000000765b4406 6 bytes [68, 80, E3, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WS2_32.dll!send 00000000765b6f01 6 bytes [68, 5F, E3, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WS2_32.dll!gethostbyname 00000000765c7673 6 bytes [68, C8, DE, 6E, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 0000000076c1c664 6 bytes [68, DC, 08, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 0000000076c1e13a 6 bytes [68, 7C, 0A, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WININET.dll!InternetReadFile 0000000076c1f8d8 6 bytes [68, 49, 09, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 0000000076c23184 6 bytes [68, 50, 0A, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 0000000076c45761 6 bytes [68, 1E, 06, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 0000000076c45fef 6 bytes [68, DA, 05, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 0000000076c4632d 6 bytes [68, 62, 06, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 0000000076c4fa49 6 bytes [68, 77, 09, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076c5f564 6 bytes [68, 0C, 07, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 0000000076c5f639 6 bytes [68, 46, 08, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 0000000076c74f2f 6 bytes [68, F6, 09, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076c7525a 6 bytes [68, B7, 06, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000076cbece5 6 bytes [68, A9, 07, 6F, 03, C3]
.text C:\Windows\SysWOW64\CTXFISPI.EXE[3308] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 0000000076cbedb7 6 bytes [68, 91, 08, 6F, 03, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076c01465 2 bytes [C0, 76]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5076] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076c014bb 2 bytes [C0, 76]
.text ... * 2
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[3864] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076c01465 2 bytes [C0, 76]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[3864] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076c014bb 2 bytes [C0, 76]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3356] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076c01465 2 bytes [C0, 76]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3356] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076c014bb 2 bytes [C0, 76]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1632:4556] 000007fef58b3e0c
Thread C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1632:4572] 000007fef58b3e0c
Thread C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [1632:4576] 000007fef12fc0d0
---- EOF - GMER 2.1 ---- MBAR Log 1.Scan: Code:
Malwarebytes Anti-Rootkit BETA 1.01.0.1021
www.malwarebytes.org
Database version: v2013.03.05.10
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Robert :: ZOCKMASCHINE [administrator]
05.03.2013 13:23:50
mbar-log-2013-03-05 (13-23-50).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 29697
Time elapsed: 1 minute(s), 42 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Tookafiq (IPH.Trojan.Zbot.Rke) -> Data: C:\Users\Robert\AppData\Roaming\Etut\uzcy.exe -> Delete on reboot.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
c:\Users\Robert\AppData\Roaming\Etut\uzcy.exe (IPH.Trojan.Zbot.Rke) -> Delete on reboot.
(end)
MBAR Log 2.Scan: Code:
Malwarebytes Anti-Rootkit BETA 1.01.0.1021
www.malwarebytes.org
Database version: v2013.03.05.10
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Robert :: ZOCKMASCHINE [administrator]
05.03.2013 13:26:55
mbar-log-2013-03-05 (13-26-55).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 29626
Time elapsed: 1 minute(s), 46 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end) |