helloagain | 07.10.2013 09:23 | Und hier noch
GMER: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-10-07 09:42:21
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-2 M4-CT256M4SSD2 rev.0309 238,47GB
Running: uywlbc81.exe; Driver: C:\Users\Calle\AppData\Local\Temp\ugldqaod.sys
---- User code sections - GMER 2.1 ----
.text C:\Programme\QNAP\Finder\iSCSIAgent.exe[1152] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000756e1465 2 bytes [6E, 75]
.text C:\Programme\QNAP\Finder\iSCSIAgent.exe[1152] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756e14bb 2 bytes [6E, 75]
.text ... * 2
.text C:\Programme\QNAP\Finder\iSCSIAgent.exe[1152] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000074e79d0b 5 bytes JMP 000000011000a4d0
.text C:\Programme\QNAP\Finder\iSCSIAgent.exe[1152] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000074e79d4e 5 bytes JMP 000000011000a630
.text C:\Programme\QNAP\Finder\iSCSIAgent.exe[1152] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 000000006d647e3d 5 bytes JMP 000000011000a690
.text C:\Programme\QNAP\Finder\iSCSIAgent.exe[1152] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006d67de69 5 bytes JMP 000000011000a770
.text C:\Programme\QNAP\Finder\iSCSIAgent.exe[1152] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006d68d2c5 5 bytes JMP 000000011000a8a0
.text C:\Programme\QNAP\Finder\iSCSIAgent.exe[1152] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006d68d371 5 bytes JMP 000000011000a990
.text C:\Programme\QNAP\Finder\iSCSIAgent.exe[1152] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006d68d429 5 bytes JMP 000000011000aa80
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000756e1465 2 bytes [6E, 75]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756e14bb 2 bytes [6E, 75]
.text ... * 2
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!init_vlc_sparse + 217 000000006ad82671 4 bytes [C0, 2D, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!init_vlc_sparse + 232 000000006ad82680 4 bytes [C0, 2D, 01, 01]
.text ... * 7
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!avcodec_get_chroma_sub_sample + 8 000000006ae63fa8 4 bytes [40, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!avcodec_get_pix_fmt_name + 14 000000006ae63fd2 4 bytes [40, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!avcodec_pix_fmt_string + 94 000000006ae64046 4 bytes [40, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!ff_is_hwaccel_pix_fmt + 10 000000006ae6408a 4 bytes [47, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!ff_fill_linesize + 36 000000006ae641b8 4 bytes [40, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!ff_fill_linesize + 150 000000006ae6422a 4 bytes [4A, 31, 01, 01]
.text ... * 7
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!ff_fill_pointer + 82 000000006ae643e6 4 bytes [46, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!ff_fill_pointer + 138 000000006ae6441e 4 bytes [46, 31, 01, 01]
.text ... * 2
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!avpicture_layout + 503 000000006ae64737 4 bytes [45, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!avpicture_layout + 554 000000006ae6476a 4 bytes [46, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!avcodec_get_pix_fmt_loss + 97 000000006ae64959 4 bytes [40, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!avcodec_get_pix_fmt_loss + 108 000000006ae64964 4 bytes [40, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!avcodec_find_best_pix_fmt + 57 000000006ae64af9 4 bytes [45, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!avcodec_find_best_pix_fmt + 91 000000006ae64b1b 4 bytes [44, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!ff_get_plane_bytewidth + 122 000000006ae64cf2 4 bytes [45, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!av_picture_copy + 352 000000006ae64e6c 4 bytes [46, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!av_picture_copy + 567 000000006ae64f43 4 bytes [45, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!av_picture_crop + 68 000000006ae65614 4 bytes [40, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!av_picture_pad + 617 000000006ae658e1 4 bytes [40, 31, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!ff_ivi_create_huff_from_desc + 209 000000006ae7d195 4 bytes [C0, 2D, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!ff_ivi_create_huff_from_desc + 342 000000006ae7d21a 4 bytes [C0, 2D, 01, 01]
.text ... * 5
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!ff_estimate_p_frame_motion + 996 000000006aeb9754 4 bytes [C0, 2B, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!ff_rle_encode + 734 000000006af4aff6 4 bytes [C1, 2B, 01, 01]
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!ff_rle_encode + 931 000000006af4b0bb 4 bytes [C0, 2B, 01, 01]
.text ... * 2
.text C:\ProgramData\TVersity\Media Server\MediaServer.exe[2560] C:\ProgramData\TVersity\Media Server\avcodec-52.dll!avcodec_align_dimensions + 21 000000006afb4965 4 bytes [45, 31, 01, 01]
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000074e79d0b 5 bytes JMP 000000011000a4d0
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000074e79d4e 5 bytes JMP 000000011000a630
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000006f54451e 5 bytes JMP 000000011000ab40
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 000000006f544b6d 5 bytes JMP 000000011000abb0
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 000000006f544bf2 5 bytes JMP 000000011000ac90
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 000000006f544f0f 5 bytes JMP 000000011000ac50
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 000000006f544f7b 5 bytes JMP 000000011000ac10
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 000000006f549054 5 bytes JMP 000000011000ad10
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000006f54adf9 5 bytes JMP 000000011000abe0
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 000000006f5652e8 5 bytes JMP 000000011000acd0
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000006f56535f 5 bytes JMP 000000011000acf0
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveInClose 000000006f5659cc 5 bytes JMP 000000011000ae40
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 000000006f565a6a 5 bytes JMP 000000011000aec0
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 000000006f565ad7 5 bytes JMP 000000011000af00
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 000000006f565b5b 5 bytes JMP 000000011000af40
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveInStart 000000006f565bba 5 bytes JMP 000000011000af80
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveInStop 000000006f565bee 5 bytes JMP 000000011000b000
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveInReset 000000006f565c22 5 bytes JMP 000000011000b060
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 000000006f565c67 5 bytes JMP 000000011000b0d0
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 000000006d647e3d 5 bytes JMP 000000011000a690
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006d67de69 5 bytes JMP 000000011000a770
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006d68d2c5 5 bytes JMP 000000011000a8a0
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006d68d371 5 bytes JMP 000000011000a990
.text C:\Windows\SysWOW64\HsMgr.exe[2616] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006d68d429 5 bytes JMP 000000011000aa80
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveOutClose 000007fef72036ac 5 bytes JMP 000007fefece01f0
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveOutUnprepareHeader 000007fef7203770 5 bytes JMP 000007fefece0298
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveOutOpen 000007fef72038d0 5 bytes JMP 000007fefece01b8
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveOutPrepareHeader 000007fef7203ca4 5 bytes JMP 000007fefece0260
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveOutWrite 000007fef7203d40 5 bytes JMP 000007fefece0228
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveInOpen 000007fef7207fe0 7 bytes JMP 000007fefece0378
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveOutReset 000007fef720a38c 5 bytes JMP 000007fefece02d0
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveOutGetVolume 000007fef72249f0 5 bytes JMP 000007fefece0308
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveOutSetVolume 000007fef7224ab0 5 bytes JMP 000007fefece0340
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveInClose 000007fef72252e0 5 bytes JMP 000007fefece03b0
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveInPrepareHeader 000007fef72253c0 5 bytes JMP 000007fefece0490
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveInUnprepareHeader 000007fef7225454 5 bytes JMP 000007fefece04c8
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveInAddBuffer 000007fef7225514 5 bytes JMP 000007fefece0500
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveInStart 000007fef72255a4 6 bytes JMP 000007fefece03e8
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveInStop 000007fef72255e4 6 bytes JMP 000007fefece0420
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveInReset 000007fef7225624 5 bytes JMP 000007fefece0458
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\WINMM.dll!waveInGetPosition 000007fef722567c 5 bytes JMP 000007fefece0538
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\DSOUND.dll!DirectSoundCreate8 000007fef5866944 7 bytes JMP 000007fefece0180
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\DSOUND.dll!DirectSoundCreate 000007fef5885a84 7 bytes JMP 000007fefece0148
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\DSOUND.dll!DirectSoundCaptureCreate 000007fef5885b90 7 bytes JMP 000007fefece0570
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\DSOUND.dll!DirectSoundCaptureCreate8 000007fef5885c94 7 bytes JMP 000007fefece05a8
.text C:\Windows\system\HsMgr64.exe[2628] C:\Windows\system32\DSOUND.dll!DirectSoundFullDuplexCreate 000007fef5885da8 5 bytes JMP 000007fefece05e0
.text C:\Programme\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe[2772] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000074e79d0b 5 bytes JMP 000000010030a4d0
.text C:\Programme\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe[2772] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000074e79d4e 5 bytes JMP 000000010030a630
.text C:\Programme\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe[2772] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000756e1465 2 bytes [6E, 75]
.text C:\Programme\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe[2772] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756e14bb 2 bytes [6E, 75]
.text ... * 2
.text C:\Programme\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe[2772] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 000000006d647e3d 5 bytes JMP 000000010030a690
.text C:\Programme\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe[2772] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006d67de69 5 bytes JMP 000000010030a770
.text C:\Programme\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe[2772] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006d68d2c5 5 bytes JMP 000000010030a8a0
.text C:\Programme\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe[2772] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006d68d371 5 bytes JMP 000000010030a990
.text C:\Programme\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe[2772] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006d68d429 5 bytes JMP 000000010030aa80
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000074e79d0b 5 bytes JMP 000000011000a4d0
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000074e79d4e 5 bytes JMP 000000011000a630
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000006f54451e 5 bytes JMP 000000011000ab40
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 000000006f544b6d 5 bytes JMP 000000011000abb0
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 000000006f544bf2 5 bytes JMP 000000011000ac90
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 000000006f544f0f 5 bytes JMP 000000011000ac50
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 000000006f544f7b 5 bytes JMP 000000011000ac10
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 000000006f549054 5 bytes JMP 000000011000ad10
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000006f54adf9 5 bytes JMP 000000011000abe0
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 000000006f5652e8 5 bytes JMP 000000011000acd0
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000006f56535f 5 bytes JMP 000000011000acf0
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveInClose 000000006f5659cc 5 bytes JMP 000000011000ae40
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 000000006f565a6a 5 bytes JMP 000000011000aec0
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 000000006f565ad7 5 bytes JMP 000000011000af00
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 000000006f565b5b 5 bytes JMP 000000011000af40
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveInStart 000000006f565bba 5 bytes JMP 000000011000af80
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveInStop 000000006f565bee 5 bytes JMP 000000011000b000
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveInReset 000000006f565c22 5 bytes JMP 000000011000b060
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 000000006f565c67 5 bytes JMP 000000011000b0d0
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 000000006d647e3d 5 bytes JMP 000000011000a690
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006d67de69 5 bytes JMP 000000011000a770
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006d68d2c5 5 bytes JMP 000000011000a8a0
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006d68d371 5 bytes JMP 000000011000a990
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006d68d429 5 bytes JMP 000000011000aa80
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000756e1465 2 bytes [6E, 75]
.text C:\Users\Calle\AppData\Local\Facebook\Messenger\2.1.4814.0\FacebookMessenger.exe[2788] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756e14bb 2 bytes [6E, 75]
.text ... * 2
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[2960] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000756e1465 2 bytes [6E, 75]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[2960] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756e14bb 2 bytes [6E, 75]
.text ... * 2
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[2960] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000074e79d0b 5 bytes JMP 000000011000a4d0
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[2960] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000074e79d4e 5 bytes JMP 000000011000a630
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[2960] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 000000006d647e3d 5 bytes JMP 000000011000a690
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[2960] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006d67de69 5 bytes JMP 000000011000a770
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[2960] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006d68d2c5 5 bytes JMP 000000011000a8a0
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[2960] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006d68d371 5 bytes JMP 000000011000a990
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe[2960] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006d68d429 5 bytes JMP 000000011000aa80
.text C:\Program Files (x86)\X-Rite\Devices\Services\xritedeviced.exe[2184] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000756e1465 2 bytes [6E, 75]
.text C:\Program Files (x86)\X-Rite\Devices\Services\xritedeviced.exe[2184] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756e14bb 2 bytes [6E, 75]
.text ... * 2
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000074e79d0b 5 bytes JMP 000000010011a4d0
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000074e79d4e 5 bytes JMP 000000010011a630
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000006f54451e 5 bytes JMP 000000010011ab40
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 000000006f544b6d 5 bytes JMP 000000010011abb0
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 000000006f544bf2 5 bytes JMP 000000010011ac90
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 000000006f544f0f 5 bytes JMP 000000010011ac50
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 000000006f544f7b 5 bytes JMP 000000010011ac10
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 000000006f549054 5 bytes JMP 000000010011ad10
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000006f54adf9 5 bytes JMP 000000010011abe0
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 000000006f5652e8 5 bytes JMP 000000010011acd0
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000006f56535f 5 bytes JMP 000000010011acf0
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveInClose 000000006f5659cc 5 bytes JMP 000000010011ae40
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 000000006f565a6a 5 bytes JMP 000000010011aec0
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 000000006f565ad7 5 bytes JMP 000000010011af00
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 000000006f565b5b 5 bytes JMP 000000010011af40
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveInStart 000000006f565bba 5 bytes JMP 000000010011af80
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveInStop 000000006f565bee 5 bytes JMP 000000010011b000
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveInReset 000000006f565c22 5 bytes JMP 000000010011b060
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 000000006f565c67 5 bytes JMP 000000010011b0d0
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 000000006d647e3d 5 bytes JMP 000000010011a690
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006d67de69 5 bytes JMP 000000010011a770
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006d68d2c5 5 bytes JMP 000000010011a8a0
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006d68d371 5 bytes JMP 000000010011a990
.text C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe[2100] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006d68d429 5 bytes JMP 000000010011aa80
.text C:\Program Files (x86)\X-Rite\Devices\Services\ColorMunki\ColorMunkiDeviceService.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000756e1465 2 bytes [6E, 75]
.text C:\Program Files (x86)\X-Rite\Devices\Services\ColorMunki\ColorMunkiDeviceService.exe[2320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756e14bb 2 bytes [6E, 75]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000074e79d0b 5 bytes JMP 000000011000a4d0
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000074e79d4e 5 bytes JMP 000000011000a630
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000006f54451e 5 bytes JMP 000000011000ab40
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 000000006f544b6d 5 bytes JMP 000000011000abb0
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 000000006f544bf2 5 bytes JMP 000000011000ac90
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 000000006f544f0f 5 bytes JMP 000000011000ac50
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 000000006f544f7b 5 bytes JMP 000000011000ac10
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 000000006f549054 5 bytes JMP 000000011000ad10
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000006f54adf9 5 bytes JMP 000000011000abe0
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 000000006f5652e8 5 bytes JMP 000000011000acd0
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000006f56535f 5 bytes JMP 000000011000acf0
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveInClose 000000006f5659cc 5 bytes JMP 000000011000ae40
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 000000006f565a6a 5 bytes JMP 000000011000aec0
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 000000006f565ad7 5 bytes JMP 000000011000af00
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 000000006f565b5b 5 bytes JMP 000000011000af40
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveInStart 000000006f565bba 5 bytes JMP 000000011000af80
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveInStop 000000006f565bee 5 bytes JMP 000000011000b000
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveInReset 000000006f565c22 5 bytes JMP 000000011000b060
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 000000006f565c67 5 bytes JMP 000000011000b0d0
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 000000006d647e3d 5 bytes JMP 000000011000a690
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006d67de69 5 bytes JMP 000000011000a770
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006d68d2c5 5 bytes JMP 000000011000a8a0
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006d68d371 5 bytes JMP 000000011000a990
.text C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe[3312] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006d68d429 5 bytes JMP 000000011000aa80
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 000000007733f9b1 8 bytes {MOV EDX, 0x90228; JMP RDX}
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 15 000000007733f9bb 1 byte [90]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007733fbf5 8 bytes {MOV EDX, 0x90268; JMP RDX}
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 15 000000007733fbff 1 byte [90]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 000000007733fc25 8 bytes {MOV EDX, 0x901a8; JMP RDX}
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 15 000000007733fc2f 1 byte [90]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 000000007733fc3d 8 bytes {MOV EDX, 0x90128; JMP RDX}
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 15 000000007733fc47 1 byte [90]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 000000007733fc55 8 bytes {MOV EDX, 0x90328; JMP RDX}
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 15 000000007733fc5f 1 byte [90]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007733fc85 8 bytes {MOV EDX, 0x90368; JMP RDX}
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 15 000000007733fc8f 1 byte [90]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 000000007733fd05 8 bytes {MOV EDX, 0x902e8; JMP RDX}
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 15 000000007733fd0f 1 byte [90]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 000000007733fd1d 8 bytes {MOV EDX, 0x902a8; JMP RDX}
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 15 000000007733fd27 1 byte [90]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 000000007733fd69 8 bytes {MOV EDX, 0x90068; JMP RDX}
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 15 000000007733fd73 1 byte [90]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 000000007733fe61 8 bytes {MOV EDX, 0x900a8; JMP RDX}
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 15 000000007733fe6b 1 byte [90]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 00000000773400b9 8 bytes {MOV EDX, 0x90028; JMP RDX}
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 15 00000000773400c3 1 byte [90]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 00000000773410c5 8 bytes {MOV EDX, 0x901e8; JMP RDX}
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 15 00000000773410cf 1 byte [90]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007734113d 8 bytes {MOV EDX, 0x90168; JMP RDX}
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 15 0000000077341147 1 byte [90]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077341341 8 bytes {MOV EDX, 0x900e8; JMP RDX}
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 15 000000007734134b 1 byte [90]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000756e1465 2 bytes [6E, 75]
.text C:\ProgramData\TVersity\Media Server\berkelium\berkelium.exe[3908] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756e14bb 2 bytes [6E, 75]
.text ... * 2
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000074e79d0b 5 bytes JMP 000000011000a4d0
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000074e79d4e 5 bytes JMP 000000011000a630
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000756e1465 2 bytes [6E, 75]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756e14bb 2 bytes [6E, 75]
.text ... * 2
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000006f54451e 5 bytes JMP 000000011000ab40
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 000000006f544b6d 5 bytes JMP 000000011000abb0
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 000000006f544bf2 5 bytes JMP 000000011000ac90
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 000000006f544f0f 5 bytes JMP 000000011000ac50
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 000000006f544f7b 5 bytes JMP 000000011000ac10
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 000000006f549054 5 bytes JMP 000000011000ad10
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000006f54adf9 5 bytes JMP 000000011000abe0
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 000000006f5652e8 5 bytes JMP 000000011000acd0
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000006f56535f 5 bytes JMP 000000011000acf0
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveInClose 000000006f5659cc 5 bytes JMP 000000011000ae40
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 000000006f565a6a 5 bytes JMP 000000011000aec0
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 000000006f565ad7 5 bytes JMP 000000011000af00
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 000000006f565b5b 5 bytes JMP 000000011000af40
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveInStart 000000006f565bba 5 bytes JMP 000000011000af80
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveInStop 000000006f565bee 5 bytes JMP 000000011000b000
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveInReset 000000006f565c22 5 bytes JMP 000000011000b060
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 000000006f565c67 5 bytes JMP 000000011000b0d0
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 000000006d647e3d 5 bytes JMP 000000011000a690
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006d67de69 5 bytes JMP 000000011000a770
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006d68d2c5 5 bytes JMP 000000011000a8a0
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006d68d371 5 bytes JMP 000000011000a990
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe[4396] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006d68d429 5 bytes JMP 000000011000aa80
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4860] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 00000000756e1465 2 bytes [6E, 75]
.text C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe[4860] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000756e14bb 2 bytes [6E, 75]
.text ... * 2
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveOutOpen 000000006f54451e 5 bytes JMP 000000011000ab40
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveOutClose 000000006f544b6d 5 bytes JMP 000000011000abb0
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveOutUnprepareHeader 000000006f544bf2 5 bytes JMP 000000011000ac90
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveOutPrepareHeader 000000006f544f0f 5 bytes JMP 000000011000ac50
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 000000006f544f7b 5 bytes JMP 000000011000ac10
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveInOpen 000000006f549054 5 bytes JMP 000000011000ad10
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveOutReset 000000006f54adf9 5 bytes JMP 000000011000abe0
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveOutGetVolume 000000006f5652e8 5 bytes JMP 000000011000acd0
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveOutSetVolume 000000006f56535f 5 bytes JMP 000000011000acf0
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveInClose 000000006f5659cc 5 bytes JMP 000000011000ae40
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveInPrepareHeader 000000006f565a6a 5 bytes JMP 000000011000aec0
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveInUnprepareHeader 000000006f565ad7 5 bytes JMP 000000011000af00
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveInAddBuffer 000000006f565b5b 5 bytes JMP 000000011000af40
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveInStart 000000006f565bba 5 bytes JMP 000000011000af80
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveInStop 000000006f565bee 5 bytes JMP 000000011000b000
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveInReset 000000006f565c22 5 bytes JMP 000000011000b060
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\WINMM.dll!waveInGetPosition 000000006f565c67 5 bytes JMP 000000011000b0d0
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate 000000006d647e3d 5 bytes JMP 000000011000a690
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCreate8 000000006d67de69 5 bytes JMP 000000011000a770
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate 000000006d68d2c5 5 bytes JMP 000000011000a8a0
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundCaptureCreate8 000000006d68d371 5 bytes JMP 000000011000a990
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\SysWOW64\DSOUND.dll!DirectSoundFullDuplexCreate 000000006d68d429 5 bytes JMP 000000011000aa80
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000074e79d0b 5 bytes JMP 000000011000a4d0
.text D:\Downloads\programme\uywlbc81.exe[3176] C:\Windows\syswow64\ole32.dll!CoCreateInstanceEx 0000000074e79d4e 5 bytes JMP 000000011000a630
---- EOF - GMER 2.1 ---- Sofern ich das richtig verstanden habe ist defrogger ja nicht notwendig als Log, solange er kein Fehler ausgeworfen hat - richtig?
Hoffe nun ist alles so wie es soll ;) |