Ich hoffe ich habe soweit alles richtig gemacht.
Es gab auch beim 2ten durchlauf keine Funde mehr.
Ich musste den GMER leider teilen die anderen logs kommen auch im nächsten beitrag!
GMER Teil 1 Code:
GMER 2.1.19155 - hxxp://www.gmer.net
Rootkit scan 2013-03-08 17:27:47
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\00000055 ST315005 rev.CC34 1397,27GB
Running: gmer_2.1.19155.exe; Driver: C:\Users\MUCCY3~1\AppData\Local\Temp\kxliiuog.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000775008fc 6 bytes [68, 93, 5C, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000775125fd 6 bytes [68, D6, FC, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007751c45a 6 bytes [68, BE, 5D, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077522a63 6 bytes [68, 1C, FD, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077544128 6 bytes [68, 62, FD, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007754e659 6 bytes [68, A8, FD, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007549455c 6 bytes [68, 27, 60, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000754979f8 6 bytes [68, E6, 5F, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007686c592 6 bytes [68, A4, 60, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000768a2538 6 bytes [68, 8D, 60, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!GetDC 00000000762e72c4 6 bytes [68, FA, B0, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000762e7446 6 bytes [68, 78, B1, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000762e7809 6 bytes [68, 2C, B8, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000762e78e2 6 bytes [68, 37, 5B, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000762e7bd3 6 bytes [68, 5F, 5B, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000762e8048 6 bytes [68, 39, B1, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000762e8a65 6 bytes [68, DA, FF, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000762eb17d 6 bytes [68, 74, 00, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000762edb98 6 bytes [68, C6, 00, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000762f05ba 6 bytes [68, 87, 5B, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000762f0d32 6 bytes [68, 0C, FF, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000762f1218 6 bytes [68, 6A, 59, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!EndPaint 00000000762f1341 6 bytes [68, 5F, B0, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000762f1361 6 bytes [68, EF, AF, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000762f2a8d 6 bytes [68, 38, 59, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!GetCapture 00000000762f2aac 6 bytes [68, 98, 5A, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000762f3391 6 bytes [68, 9F, B0, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000762f434b 6 bytes [68, 27, 00, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000762f5f74 6 bytes [68, B2, 5B, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000762f6222 6 bytes [68, 4B, B2, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000762f792f 6 bytes [68, 55, FF, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000762f7fbb 6 bytes [68, 37, FE, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000762f810c 6 bytes [68, C6, FE, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000762f85c1 6 bytes [68, EE, FD, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000762f86b4 6 bytes [68, 80, FE, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007630d41f 6 bytes [68, B8, B1, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!ReleaseCapture 000000007630ed49 6 bytes [68, 48, 5A, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!SetCapture 000000007630ed56 6 bytes [68, EE, 59, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000076329854 6 bytes [68, B8, FC, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000076329cfd 6 bytes [68, B1, 59, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000076329f1d 6 bytes [68, DB, B9, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000763487cb 6 bytes [68, 68, FC, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075443918 6 bytes [68, D4, 06, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075444296 6 bytes [68, E5, 02, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075444406 6 bytes [68, 2D, 07, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WS2_32.dll!send 0000000075446f01 6 bytes [68, 0C, 07, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075457673 6 bytes [68, 75, 02, 08, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000076bb1224 6 bytes [68, 51, 5C, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 00000000763ea336 6 bytes [68, 16, 74, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 00000000763eab41 6 bytes [68, 76, 72, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WININET.dll!InternetReadFile 00000000763eb3fe 6 bytes [68, E3, 72, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 00000000763f4a42 6 bytes [68, 74, 6F, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000763f4c7d 6 bytes [68, B8, 6F, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000763f5e5d 6 bytes [68, EA, 73, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000763fba12 6 bytes [68, FC, 6F, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 00000000764045e2 6 bytes [68, E0, 71, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076404a35 6 bytes [68, A6, 70, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 000000007641ae56 6 bytes [68, 11, 73, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007644b04e 6 bytes [68, 90, 73, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000076461962 6 bytes [68, 43, 71, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000764619e5 6 bytes [68, 2B, 72, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe[2728] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076461a48 6 bytes [68, 51, 70, 07, 02, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000775008fc 6 bytes [68, 93, 5C, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000775125fd 6 bytes [68, D6, FC, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007751c45a 6 bytes [68, BE, 5D, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077522a63 6 bytes [68, 1C, FD, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077544128 6 bytes [68, 62, FD, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007754e659 6 bytes [68, A8, FD, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007549455c 6 bytes [68, 27, 60, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000754979f8 6 bytes [68, E6, 5F, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007686c592 6 bytes [68, A4, 60, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000768a2538 6 bytes [68, 8D, 60, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!GetDC 00000000762e72c4 6 bytes [68, FA, B0, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000762e7446 6 bytes [68, 78, B1, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000762e7809 6 bytes [68, 2C, B8, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000762e78e2 6 bytes [68, 37, 5B, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000762e7bd3 6 bytes [68, 5F, 5B, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000762e8048 6 bytes [68, 39, B1, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000762e8a65 6 bytes [68, DA, FF, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000762eb17d 6 bytes [68, 74, 00, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000762edb98 6 bytes [68, C6, 00, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000762f05ba 6 bytes [68, 87, 5B, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000762f0d32 6 bytes [68, 0C, FF, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000762f1218 6 bytes [68, 6A, 59, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!EndPaint 00000000762f1341 6 bytes [68, 5F, B0, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000762f1361 6 bytes [68, EF, AF, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000762f2a8d 6 bytes [68, 38, 59, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!GetCapture 00000000762f2aac 6 bytes [68, 98, 5A, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000762f3391 6 bytes [68, 9F, B0, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000762f434b 6 bytes [68, 27, 00, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000762f5f74 6 bytes [68, B2, 5B, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000762f6222 6 bytes [68, 4B, B2, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000762f792f 6 bytes [68, 55, FF, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000762f7fbb 6 bytes [68, 37, FE, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000762f810c 6 bytes [68, C6, FE, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000762f85c1 6 bytes [68, EE, FD, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000762f86b4 6 bytes [68, 80, FE, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007630d41f 6 bytes [68, B8, B1, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!ReleaseCapture 000000007630ed49 6 bytes [68, 48, 5A, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!SetCapture 000000007630ed56 6 bytes [68, EE, 59, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000076329854 6 bytes [68, B8, FC, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000076329cfd 6 bytes [68, B1, 59, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000076329f1d 6 bytes [68, DB, B9, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000763487cb 6 bytes [68, 68, FC, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075443918 6 bytes [68, D4, 06, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075444296 6 bytes [68, E5, 02, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075444406 6 bytes [68, 2D, 07, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WS2_32.dll!send 0000000075446f01 6 bytes [68, 0C, 07, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075457673 6 bytes [68, 75, 02, 07, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000076bb1224 6 bytes [68, 51, 5C, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 00000000763ea336 6 bytes [68, 16, 74, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 00000000763eab41 6 bytes [68, 76, 72, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WININET.dll!InternetReadFile 00000000763eb3fe 6 bytes [68, E3, 72, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 00000000763f4a42 6 bytes [68, 74, 6F, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000763f4c7d 6 bytes [68, B8, 6F, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000763f5e5d 6 bytes [68, EA, 73, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000763fba12 6 bytes [68, FC, 6F, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 00000000764045e2 6 bytes [68, E0, 71, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076404a35 6 bytes [68, A6, 70, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 000000007641ae56 6 bytes [68, 11, 73, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007644b04e 6 bytes [68, 90, 73, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000076461962 6 bytes [68, 43, 71, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000764619e5 6 bytes [68, 2B, 72, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076461a48 6 bytes [68, 51, 70, 06, 03, C3]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000753a1465 2 bytes [3A, 75]
.text C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe[2776] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000753a14bb 2 bytes [3A, 75]
.text ... * 2
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000775008fc 6 bytes [68, 93, 5C, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000775125fd 6 bytes [68, D6, FC, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007751c45a 6 bytes [68, BE, 5D, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077522a63 6 bytes [68, 1C, FD, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077544128 6 bytes [68, 62, FD, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007754e659 6 bytes [68, A8, FD, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007549455c 6 bytes [68, 27, 60, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000754979f8 6 bytes [68, E6, 5F, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!GetDC 00000000762e72c4 6 bytes [68, FA, B0, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000762e7446 6 bytes [68, 78, B1, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000762e7809 6 bytes [68, 2C, B8, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000762e78e2 6 bytes [68, 37, 5B, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000762e7bd3 6 bytes [68, 5F, 5B, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000762e8048 6 bytes [68, 39, B1, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000762e8a65 6 bytes [68, DA, FF, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000762eb17d 6 bytes [68, 74, 00, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000762edb98 6 bytes [68, C6, 00, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000762f05ba 6 bytes [68, 87, 5B, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000762f0d32 6 bytes [68, 0C, FF, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000762f1218 6 bytes [68, 6A, 59, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!EndPaint 00000000762f1341 6 bytes [68, 5F, B0, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000762f1361 6 bytes [68, EF, AF, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000762f2a8d 6 bytes [68, 38, 59, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!GetCapture 00000000762f2aac 6 bytes [68, 98, 5A, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000762f3391 6 bytes [68, 9F, B0, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000762f434b 6 bytes [68, 27, 00, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000762f5f74 6 bytes [68, B2, 5B, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000762f6222 6 bytes [68, 4B, B2, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000762f792f 6 bytes [68, 55, FF, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000762f7fbb 6 bytes [68, 37, FE, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000762f810c 6 bytes [68, C6, FE, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000762f85c1 6 bytes [68, EE, FD, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000762f86b4 6 bytes [68, 80, FE, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007630d41f 6 bytes [68, B8, B1, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!ReleaseCapture 000000007630ed49 6 bytes [68, 48, 5A, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!SetCapture 000000007630ed56 6 bytes [68, EE, 59, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000076329854 6 bytes [68, B8, FC, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000076329cfd 6 bytes [68, B1, 59, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000076329f1d 6 bytes [68, DB, B9, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000763487cb 6 bytes [68, 68, FC, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007686c592 6 bytes [68, A4, 60, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000768a2538 6 bytes [68, 8D, 60, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075443918 6 bytes [68, D4, 06, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075444296 6 bytes [68, E5, 02, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075444406 6 bytes [68, 2D, 07, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WS2_32.dll!send 0000000075446f01 6 bytes [68, 0C, 07, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075457673 6 bytes [68, 75, 02, B3, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000076bb1224 6 bytes [68, 51, 5C, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 00000000763ea336 6 bytes [68, 16, 74, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 00000000763eab41 6 bytes [68, 76, 72, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WININET.dll!InternetReadFile 00000000763eb3fe 6 bytes [68, E3, 72, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 00000000763f4a42 6 bytes [68, 74, 6F, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000763f4c7d 6 bytes [68, B8, 6F, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000763f5e5d 6 bytes [68, EA, 73, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000763fba12 6 bytes [68, FC, 6F, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 00000000764045e2 6 bytes [68, E0, 71, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076404a35 6 bytes [68, A6, 70, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 000000007641ae56 6 bytes [68, 11, 73, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007644b04e 6 bytes [68, 90, 73, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000076461962 6 bytes [68, 43, 71, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000764619e5 6 bytes [68, 2B, 72, B2, 02, C3]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[3044] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076461a48 6 bytes [68, 51, 70, B2, 02, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000775008fc 4 bytes [68, 93, 5C, 73]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077500901 1 byte [C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000775125fd 6 bytes [68, D6, FC, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007751c45a 6 bytes [68, BE, 5D, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077522a63 6 bytes [68, 1C, FD, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077544128 6 bytes [68, 62, FD, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007754e659 6 bytes [68, A8, FD, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007549455c 6 bytes [68, 27, 60, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000754979f8 6 bytes [68, E6, 5F, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!GetDC 00000000762e72c4 4 bytes [68, FA, B0, 72]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000762e72c9 1 byte [C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000762e7446 6 bytes [68, 78, B1, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000762e7809 6 bytes [68, 2C, B8, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000762e78e2 6 bytes [68, 37, 5B, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000762e7bd3 6 bytes [68, 5F, 5B, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000762e8048 4 bytes [68, 39, B1, 72]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000762e804d 1 byte [C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000762e8a65 6 bytes [68, DA, FF, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000762eb17d 6 bytes [68, 74, 00, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000762edb98 6 bytes [68, C6, 00, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000762f05ba 6 bytes [68, 87, 5B, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000762f0d32 6 bytes [68, 0C, FF, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000762f1218 6 bytes [68, 6A, 59, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!EndPaint 00000000762f1341 4 bytes [68, 5F, B0, 72]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!EndPaint + 5 00000000762f1346 1 byte [C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000762f1361 4 bytes [68, EF, AF, 72]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 00000000762f1366 1 byte [C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000762f2a8d 6 bytes [68, 38, 59, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!GetCapture 00000000762f2aac 6 bytes [68, 98, 5A, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000762f3391 4 bytes [68, 9F, B0, 72]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 00000000762f3396 1 byte [C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000762f434b 6 bytes [68, 27, 00, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000762f5f74 6 bytes [68, B2, 5B, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000762f6222 6 bytes [68, 4B, B2, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000762f792f 6 bytes [68, 55, FF, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000762f7fbb 6 bytes [68, 37, FE, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000762f810c 6 bytes [68, C6, FE, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000762f85c1 6 bytes [68, EE, FD, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000762f86b4 6 bytes [68, 80, FE, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007630d41f 6 bytes [68, B8, B1, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!ReleaseCapture 000000007630ed49 6 bytes [68, 48, 5A, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!SetCapture 000000007630ed56 4 bytes [68, EE, 59, 73]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!SetCapture + 5 000000007630ed5b 1 byte [C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000076329854 6 bytes [68, B8, FC, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000076329cfd 6 bytes [68, B1, 59, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000076329f1d 6 bytes [68, DB, B9, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000763487cb 4 bytes [68, 68, FC, 72]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 00000000763487d0 1 byte [C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007686c592 6 bytes [68, A4, 60, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000768a2538 6 bytes [68, 8D, 60, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000076bb1224 6 bytes [68, 51, 5C, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075443918 6 bytes [68, D4, 06, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075444296 6 bytes [68, E5, 02, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075444406 6 bytes [68, 2D, 07, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WS2_32.dll!send 0000000075446f01 6 bytes [68, 0C, 07, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075457673 6 bytes [68, 75, 02, 73, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 00000000763ea336 6 bytes [68, 16, 74, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 00000000763eab41 6 bytes [68, 76, 72, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WININET.dll!InternetReadFile 00000000763eb3fe 6 bytes [68, E3, 72, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 00000000763f4a42 6 bytes [68, 74, 6F, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000763f4c7d 6 bytes [68, B8, 6F, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000763f5e5d 6 bytes [68, EA, 73, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000763fba12 6 bytes [68, FC, 6F, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 00000000764045e2 6 bytes [68, E0, 71, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076404a35 6 bytes [68, A6, 70, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 000000007641ae56 6 bytes [68, 11, 73, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007644b04e 6 bytes [68, 90, 73, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000076461962 6 bytes [68, 43, 71, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000764619e5 6 bytes [68, 2B, 72, 72, 00, C3]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3060] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076461a48 6 bytes [68, 51, 70, 72, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000775008fc 4 bytes [68, 93, 5C, 43]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077500901 1 byte [C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000775125fd 6 bytes [68, D6, FC, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007751c45a 6 bytes [68, BE, 5D, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077522a63 6 bytes [68, 1C, FD, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077544128 6 bytes [68, 62, FD, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007754e659 6 bytes [68, A8, FD, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007549455c 6 bytes [68, 27, 60, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000754979f8 6 bytes [68, E6, 5F, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!GetDC 00000000762e72c4 4 bytes [68, FA, B0, 42]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000762e72c9 1 byte [C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000762e7446 6 bytes [68, 78, B1, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000762e7809 6 bytes [68, 2C, B8, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000762e78e2 6 bytes [68, 37, 5B, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000762e7bd3 6 bytes [68, 5F, 5B, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000762e8048 4 bytes [68, 39, B1, 42]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000762e804d 1 byte [C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000762e8a65 6 bytes [68, DA, FF, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000762eb17d 6 bytes [68, 74, 00, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000762edb98 6 bytes [68, C6, 00, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000762f05ba 6 bytes [68, 87, 5B, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000762f0d32 6 bytes [68, 0C, FF, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000762f1218 6 bytes [68, 6A, 59, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!EndPaint 00000000762f1341 4 bytes [68, 5F, B0, 42]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!EndPaint + 5 00000000762f1346 1 byte [C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000762f1361 4 bytes [68, EF, AF, 42]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 00000000762f1366 1 byte [C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000762f2a8d 6 bytes [68, 38, 59, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!GetCapture 00000000762f2aac 6 bytes [68, 98, 5A, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000762f3391 4 bytes [68, 9F, B0, 42]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 00000000762f3396 1 byte [C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000762f434b 6 bytes [68, 27, 00, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000762f5f74 6 bytes [68, B2, 5B, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000762f6222 6 bytes [68, 4B, B2, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000762f792f 6 bytes [68, 55, FF, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000762f7fbb 6 bytes [68, 37, FE, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000762f810c 6 bytes [68, C6, FE, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000762f85c1 6 bytes [68, EE, FD, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000762f86b4 6 bytes [68, 80, FE, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007630d41f 6 bytes [68, B8, B1, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!ReleaseCapture 000000007630ed49 6 bytes [68, 48, 5A, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!SetCapture 000000007630ed56 4 bytes [68, EE, 59, 43]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!SetCapture + 5 000000007630ed5b 1 byte [C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000076329854 6 bytes [68, B8, FC, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000076329cfd 6 bytes [68, B1, 59, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000076329f1d 6 bytes [68, DB, B9, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000763487cb 4 bytes [68, 68, FC, 42]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 00000000763487d0 1 byte [C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007686c592 6 bytes [68, A4, 60, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000768a2538 6 bytes [68, 8D, 60, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075443918 6 bytes [68, D4, 06, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075444296 6 bytes [68, E5, 02, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075444406 6 bytes [68, 2D, 07, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WS2_32.dll!send 0000000075446f01 6 bytes [68, 0C, 07, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075457673 6 bytes [68, 75, 02, 43, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000076bb1224 6 bytes [68, 51, 5C, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 00000000763ea336 6 bytes [68, 16, 74, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 00000000763eab41 6 bytes [68, 76, 72, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WININET.dll!InternetReadFile 00000000763eb3fe 6 bytes [68, E3, 72, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 00000000763f4a42 6 bytes [68, 74, 6F, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000763f4c7d 6 bytes [68, B8, 6F, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000763f5e5d 6 bytes [68, EA, 73, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000763fba12 6 bytes [68, FC, 6F, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 00000000764045e2 6 bytes [68, E0, 71, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076404a35 6 bytes [68, A6, 70, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 000000007641ae56 6 bytes [68, 11, 73, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007644b04e 6 bytes [68, 90, 73, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000076461962 6 bytes [68, 43, 71, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000764619e5 6 bytes [68, 2B, 72, 42, 00, C3]
.text C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe[2640] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076461a48 6 bytes [68, 51, 70, 42, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000775008fc 4 bytes [68, 93, 5C, 21]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077500901 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000775125fd 6 bytes [68, D6, FC, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007751c45a 6 bytes [68, BE, 5D, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077522a63 6 bytes [68, 1C, FD, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077544128 6 bytes [68, 62, FD, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007754e659 6 bytes [68, A8, FD, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007549455c 6 bytes [68, 27, 60, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000754979f8 6 bytes [68, E6, 5F, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007686c592 6 bytes [68, A4, 60, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000768a2538 6 bytes [68, 8D, 60, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!GetDC 00000000762e72c4 4 bytes [68, FA, B0, 20]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000762e72c9 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000762e7446 6 bytes [68, 78, B1, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000762e7809 6 bytes [68, 2C, B8, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000762e78e2 6 bytes [68, 37, 5B, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000762e7bd3 6 bytes [68, 5F, 5B, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000762e8048 4 bytes [68, 39, B1, 20]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000762e804d 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000762e8a65 6 bytes [68, DA, FF, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000762eb17d 6 bytes [68, 74, 00, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000762edb98 6 bytes [68, C6, 00, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000762f05ba 6 bytes [68, 87, 5B, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000762f0d32 6 bytes [68, 0C, FF, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000762f1218 6 bytes [68, 6A, 59, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!EndPaint 00000000762f1341 4 bytes [68, 5F, B0, 20]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!EndPaint + 5 00000000762f1346 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000762f1361 4 bytes [68, EF, AF, 20]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 00000000762f1366 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000762f2a8d 6 bytes [68, 38, 59, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!GetCapture 00000000762f2aac 6 bytes [68, 98, 5A, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000762f3391 4 bytes [68, 9F, B0, 20]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 00000000762f3396 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000762f434b 6 bytes [68, 27, 00, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000762f5f74 6 bytes [68, B2, 5B, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000762f6222 6 bytes [68, 4B, B2, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000762f792f 6 bytes [68, 55, FF, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000762f7fbb 6 bytes [68, 37, FE, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000762f810c 6 bytes [68, C6, FE, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000762f85c1 6 bytes [68, EE, FD, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000762f86b4 6 bytes [68, 80, FE, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007630d41f 6 bytes [68, B8, B1, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!ReleaseCapture 000000007630ed49 6 bytes [68, 48, 5A, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!SetCapture 000000007630ed56 4 bytes [68, EE, 59, 21]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!SetCapture + 5 000000007630ed5b 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000076329854 6 bytes [68, B8, FC, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000076329cfd 6 bytes [68, B1, 59, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000076329f1d 6 bytes [68, DB, B9, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000763487cb 4 bytes [68, 68, FC, 20]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 00000000763487d0 1 byte [C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075443918 6 bytes [68, D4, 06, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075444296 6 bytes [68, E5, 02, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075444406 6 bytes [68, 2D, 07, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WS2_32.dll!send 0000000075446f01 6 bytes [68, 0C, 07, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075457673 6 bytes [68, 75, 02, 21, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000076bb1224 6 bytes [68, 51, 5C, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 00000000763ea336 6 bytes [68, 16, 74, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 00000000763eab41 6 bytes [68, 76, 72, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WININET.dll!InternetReadFile 00000000763eb3fe 6 bytes [68, E3, 72, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 00000000763f4a42 6 bytes [68, 74, 6F, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000763f4c7d 6 bytes [68, B8, 6F, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000763f5e5d 6 bytes [68, EA, 73, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000763fba12 6 bytes [68, FC, 6F, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 00000000764045e2 6 bytes [68, E0, 71, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076404a35 6 bytes [68, A6, 70, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 000000007641ae56 6 bytes [68, 11, 73, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007644b04e 6 bytes [68, 90, 73, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000076461962 6 bytes [68, 43, 71, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000764619e5 6 bytes [68, 2B, 72, 20, 00, C3]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[1432] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076461a48 6 bytes [68, 51, 70, 20, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 00000000775008fc 4 bytes [68, 93, 5C, 2B]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077500901 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 00000000775125fd 6 bytes [68, D6, FC, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007751c45a 6 bytes [68, BE, 5D, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077522a63 6 bytes [68, 1C, FD, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077544128 6 bytes [68, 62, FD, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007754e659 6 bytes [68, A8, FD, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 000000007549455c 6 bytes [68, 27, 60, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000754979f8 6 bytes [68, E6, 5F, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007686c592 6 bytes [68, A4, 60, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000768a2538 6 bytes [68, 8D, 60, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!GetDC 00000000762e72c4 4 bytes [68, FA, B0, 2A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!GetDC + 5 00000000762e72c9 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!ReleaseDC 00000000762e7446 6 bytes [68, 78, B1, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!TranslateMessage 00000000762e7809 6 bytes [68, 2C, B8, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!GetMessageW 00000000762e78e2 6 bytes [68, 37, 5B, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!GetMessageA 00000000762e7bd3 6 bytes [68, 5F, 5B, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!GetWindowDC 00000000762e8048 4 bytes [68, 39, B1, 2A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 00000000762e804d 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!RegisterClassW 00000000762e8a65 6 bytes [68, DA, FF, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!RegisterClassExW 00000000762eb17d 6 bytes [68, 74, 00, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!RegisterClassExA 00000000762edb98 6 bytes [68, C6, 00, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!PeekMessageW 00000000762f05ba 6 bytes [68, 87, 5B, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!CallWindowProcW 00000000762f0d32 6 bytes [68, 0C, FF, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!GetCursorPos 00000000762f1218 6 bytes [68, 6A, 59, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!EndPaint 00000000762f1341 4 bytes [68, 5F, B0, 2A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!EndPaint + 5 00000000762f1346 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!BeginPaint 00000000762f1361 4 bytes [68, EF, AF, 2A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 00000000762f1366 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!GetMessagePos 00000000762f2a8d 6 bytes [68, 38, 59, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!GetCapture 00000000762f2aac 6 bytes [68, 98, 5A, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!GetDCEx 00000000762f3391 4 bytes [68, 9F, B0, 2A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 00000000762f3396 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!RegisterClassA 00000000762f434b 6 bytes [68, 27, 00, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!PeekMessageA 00000000762f5f74 6 bytes [68, B2, 5B, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 00000000762f6222 6 bytes [68, 4B, B2, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!CallWindowProcA 00000000762f792f 6 bytes [68, 55, FF, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!DefFrameProcA 00000000762f7fbb 6 bytes [68, 37, FE, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 00000000762f810c 6 bytes [68, C6, FE, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!DefFrameProcW 00000000762f85c1 6 bytes [68, EE, FD, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 00000000762f86b4 6 bytes [68, 80, FE, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!GetUpdateRect 000000007630d41f 6 bytes [68, B8, B1, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!ReleaseCapture 000000007630ed49 6 bytes [68, 48, 5A, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!SetCapture 000000007630ed56 4 bytes [68, EE, 59, 2B]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!SetCapture + 5 000000007630ed5b 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000076329854 6 bytes [68, B8, FC, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000076329cfd 6 bytes [68, B1, 59, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000076329f1d 6 bytes [68, DB, B9, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 00000000763487cb 4 bytes [68, 68, FC, 2A]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 00000000763487d0 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 00000000763ea336 6 bytes [68, 16, 74, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 00000000763eab41 6 bytes [68, 76, 72, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WININET.dll!InternetReadFile 00000000763eb3fe 6 bytes [68, E3, 72, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 00000000763f4a42 6 bytes [68, 74, 6F, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000763f4c7d 6 bytes [68, B8, 6F, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000763f5e5d 6 bytes [68, EA, 73, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000763fba12 6 bytes [68, FC, 6F, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 00000000764045e2 6 bytes [68, E0, 71, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 0000000076404a35 6 bytes [68, A6, 70, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 000000007641ae56 6 bytes [68, 11, 73, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007644b04e 6 bytes [68, 90, 73, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 0000000076461962 6 bytes [68, 43, 71, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000764619e5 6 bytes [68, 2B, 72, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 0000000076461a48 6 bytes [68, 51, 70, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000076bb1224 6 bytes [68, 51, 5C, 2A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075443918 6 bytes [68, D4, 06, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075444296 6 bytes [68, E5, 02, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075444406 6 bytes [68, 2D, 07, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WS2_32.dll!send 0000000075446f01 6 bytes [68, 0C, 07, 2B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[992] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075457673 6 bytes [68, 75, 02, 2B, 00, C3]
.text C:\Users\Muccy3001\AppData\Roaming\Urobz\taqeh.exe[3096] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000075444296 6 bytes [68, E5, 02, 42, 00, C3]
.text C:\Users\Muccy3001\AppData\Roaming\Urobz\taqeh.exe[3096] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000075457673 6 bytes [68, 75, 02, 42, 00, C3]
.text C:\Users\Muccy3001\AppData\Roaming\Urobz\taqeh.exe[3096] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000753a1465 2 bytes [3A, 75]
.text C:\Users\Muccy3001\AppData\Roaming\Urobz\taqeh.exe[3096] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000753a14bb 2 bytes [3A, 75]
.text ...
|