alex_esp | 14.11.2013 16:13 | Der Frst-Code ist einzeln schon zu lang. Soll ich ihn dann auf mehrere Posts aufteilen? 3 wären notwendig. Deshalb hatte ihn gleich als Zip angehängt.
Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-11-2013
Ran by Alexander at 2013-11-14 13:20:33
Running from C:\Users\Alexander\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Sophos Anti-Virus (Enabled - Up to date) {65FBD860-96D8-75EF-C7ED-7BE27E6C498A}
AV: Avira Desktop (Enabled - Out of date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Enabled - Out of date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Sophos Anti-Virus (Enabled - Up to date) {DE9A3984-B0E2-7A61-FD5D-409005EB0337}
==================== Installed Programs ======================
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.117)
Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05)
Akamai NetSession Interface (HKCU)
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 1.0.0.36)
AutoCAD 2013 - Deutsch (German) (Version: 19.0.55.0)
AutoCAD 2013 Language Pack - Deutsch (German) (Version: 19.0.55.0)
Autodesk 3ds Max 2013 64-bit (Version: 15.0.0.347)
Autodesk Backburner 2013.0.0 (x32 Version: 2013.0.0)
Autodesk Content Service (x32 Version: 3.0.84.0)
Autodesk Content Service Language Pack (x32 Version: 3.0.84.0)
Autodesk DirectConnect 2013 64-bit (Version: 7.0.28.0)
Autodesk Download Manager (x32 Version: 2.0.6.0)
Autodesk Essential Skills Movies for 3ds Max 2013 64-bit (Version: 1.0.0.1)
Autodesk FBX Plug-in 2013.1 - 3ds Max 2013 64-bit
Autodesk Inventor Server Engine for 3ds Max 2013 64-bit (Version: 15.0)
Autodesk Material Library 2013 (x32 Version: 3.0.13)
Autodesk Material Library Base Resolution Image Library 2013 (x32 Version: 3.0.13)
Autodesk Material Library Medium Resolution Image Library 2013 (x32 Version: 3.0.13)
Autodesk Revit Interoperability for 3ds Max and 3ds Max Design 2013 64-bit (Version: 1.0.0.1)
Autodesk Sync (Version: 3.5.24.0)
Avira Free Antivirus (x32 Version: 14.0.0.411)
Composite 2013 64-bit (Version: 8.0.0)
Conexant HD Audio (Version: 8.54.1.55)
FARO LS 1.1.406.58 (x32 Version: 4.6.58.2)
GeForce Experience NvStream Client Components (Version: 1.6.28)
gvSIG desktop (x32 Version: 1.12.0)
Intel PROSet Wireless
Intel(R) Processor Graphics (x32 Version: 9.17.10.2932)
Intel(R) PROSet/Wireless WiFi-Software (Version: 14.00.20110)
Intel(R) Rapid Storage Technology (x32 Version: 10.1.2.1004)
Java 7 Update 45 (x32 Version: 7.0.450)
Java Auto Updater (x32 Version: 2.1.9.8)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
NVIDIA GeForce Experience 1.7.1 (Version: 1.7.1)
NVIDIA Grafiktreiber 331.65 (Version: 331.65)
NVIDIA Install Application (Version: 2.1002.140.952)
NVIDIA LED Visualizer 1.0 (Version: 1.0)
NVIDIA Optimus 9.3.21 (Version: 9.3.21)
NVIDIA PhysX (x32 Version: 9.13.0725)
NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725)
NVIDIA ShadowPlay 9.3.21 (Version: 9.3.21)
NVIDIA Systemsteuerung 331.65 (Version: 331.65)
NVIDIA Update 9.3.21 (Version: 9.3.21)
NVIDIA Update Components (Version: 9.3.21)
NVIDIA Virtual Audio 1.2.9 (Version: 1.2.9)
OpenOffice 4.0.1 (x32 Version: 4.01.9714)
Opera Mail 1.0 (HKCU Version: 1.0.1040)
Opera Stable 17.0.1241.53 (x32 Version: 17.0.1241.53)
Realtek PCIE Card Reader (x32 Version: 6.1.7601.85)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.26.0)
SHIELD Streaming (Version: 1.6.53)
Skype™ 6.10 (x32 Version: 6.10.104)
Sophos Anti-Virus (x32 Version: 10.3.1)
Sophos AutoUpdate (x32 Version: 2.9.0.344)
Synaptics Pointing Device Driver (Version: 15.2.9.0)
System Requirements Lab for Intel (x32 Version: 4.5.15.0)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3)
Windows Phone app for desktop (x32 Version: 1.0.1720.1)
==================== Restore Points =========================
01-11-2013 21:44:19 Installed Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
01-11-2013 21:44:29 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
01-11-2013 21:47:59 OpenOffice 4.0.1 wird installiert
05-11-2013 13:15:02 Windows Update
10-11-2013 23:35:09 Installed Windows Phone app for desktop
14-11-2013 09:47:56 Windows Update
==================== Hosts content: ==========================
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {3B3FE29F-E3F8-49FB-8CDA-CF1F7E566436} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation)
==================== Loaded Modules (whitelisted) =============
2012-12-14 02:42 - 2012-12-14 02:42 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2013-11-11 00:07 - 2013-10-10 19:14 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2013-10-30 17:54 - 2013-10-21 07:41 - 00868704 _____ () C:\Program Files (x86)\Opera\17.0.1241.53\ffmpegsumo.dll
2013-10-30 17:54 - 2013-10-21 07:42 - 00881504 _____ () C:\Program Files (x86)\Opera\17.0.1241.53\libglesv2.dll
2013-10-30 17:54 - 2013-10-21 07:42 - 00109408 _____ () C:\Program Files (x86)\Opera\17.0.1241.53\libegl.dll
2013-10-30 14:13 - 2013-10-30 14:13 - 16233864 _____ () C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll
2013-10-30 19:20 - 2013-10-30 19:20 - 00169472 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\9ab0e818cb3d1b6930eba54179f89300\IsdiInterop.ni.dll
2013-10-30 15:00 - 2011-01-12 17:56 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SAVService => ""="service"
==================== Faulty Device Manager Devices =============
Name: SM-Bus-Controller
Description: SM-Bus-Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (11/14/2013 00:22:14 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/11/2013 01:20:01 AM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/11/2013 00:24:02 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Die E/A-Schreibvorgänge können während des Schattenkopie-Erstellungszeitraums auf Volume "C:\" nicht gespeichert werden.
Der Volumeindex im Schattenkopiesatz ist 0. Fehlerdetails: Offen[0x00000000, Der Vorgang wurde erfolgreich beendet.
], Leerung[0x00000000, Der Vorgang wurde erfolgreich beendet.
], Freigabe[0x80042314, Der Schattenkopieanbieter hat beim Warten auf den Schreibvorgang auf das Volume, von dem eine Schattenkopie erstellt wird, das Zeitlimit überschritten. Ursache hierfür könnte eine durch eine Anwendung oder einen Systemdienst verursachte hohe Aktivität auf dem Volume sein. Wiederholen Sie den Vorgang später, wenn das Volume nicht so stark ausgelastet ist.
], Ausführung[0x00000000, Der Vorgang wurde erfolgreich beendet.
].
Vorgang:
Asynchroner Vorgang wird ausgeführt
Kontext:
Aktueller Status: DoSnapshotSet
Error: (11/11/2013 00:24:02 AM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Die Schattenkopie kann nicht zugesichert werden - Vorgang hat das Zeitlimit überschritten.
Fehlerkontext: DeviceIoControl(\\?\Volume{604e0bc4-4155-11e3-ad8d-806e6f6e6963} - 0000000000000134,0x0053c010,00000000001DE750,0,0000000000377FA0,4096,[0]).
Vorgang:
Schattenkopien werden übertragen
Kontext:
Ausführungskontext: System Provider
Error: (11/10/2013 06:59:24 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/07/2013 01:13:41 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/06/2013 09:48:44 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/06/2013 09:25:10 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (11/02/2013 02:01:38 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc3c1
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000016eef
ID des fehlerhaften Prozesses: 0x388
Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0
Pfad der fehlerhaften Anwendung: svchost.exe1
Pfad des fehlerhaften Moduls: svchost.exe2
Berichtskennung: svchost.exe3
Error: (11/01/2013 04:33:50 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1".
Die abhängige Assemblierung "Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
System errors:
=============
Error: (11/14/2013 11:39:10 AM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
Error: (11/14/2013 11:14:50 AM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error: (11/14/2013 11:14:50 AM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error: (11/14/2013 11:14:48 AM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error: (11/14/2013 11:14:44 AM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error: (11/14/2013 11:14:44 AM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error: (11/14/2013 11:14:43 AM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk1\DR1 gefunden.
Error: (11/13/2013 00:40:58 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR3 gefunden.
Error: (11/13/2013 00:40:57 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR3 gefunden.
Error: (11/13/2013 00:40:57 PM) (Source: Disk) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR3 gefunden.
Microsoft Office Sessions:
=========================
Error: (11/14/2013 00:22:14 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Autodesk\Composite 2013\python\lib\distutils\command\wininst-8_d.exe
Error: (11/11/2013 01:20:01 AM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Autodesk\Composite 2013\python\lib\distutils\command\wininst-8_d.exe
Error: (11/11/2013 00:24:02 AM) (Source: VSS)(User: )
Description: C:\00x00000000, Der Vorgang wurde erfolgreich beendet.
0x00000000, Der Vorgang wurde erfolgreich beendet.
0x80042314, Der Schattenkopieanbieter hat beim Warten auf den Schreibvorgang auf das Volume, von dem eine Schattenkopie erstellt wird, das Zeitlimit überschritten. Ursache hierfür könnte eine durch eine Anwendung oder einen Systemdienst verursachte hohe Aktivität auf dem Volume sein. Wiederholen Sie den Vorgang später, wenn das Volume nicht so stark ausgelastet ist.
0x00000000, Der Vorgang wurde erfolgreich beendet.
Vorgang:
Asynchroner Vorgang wird ausgeführt
Kontext:
Aktueller Status: DoSnapshotSet
Error: (11/11/2013 00:24:02 AM) (Source: VSS)(User: )
Description: DeviceIoControl(\\?\Volume{604e0bc4-4155-11e3-ad8d-806e6f6e6963} - 0000000000000134,0x0053c010,00000000001DE750,0,0000000000377FA0,4096,[0])
Vorgang:
Schattenkopien werden übertragen
Kontext:
Ausführungskontext: System Provider
Error: (11/10/2013 06:59:24 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Autodesk\Composite 2013\python\lib\distutils\command\wininst-8_d.exe
Error: (11/07/2013 01:13:41 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Autodesk\Composite 2013\python\lib\distutils\command\wininst-8_d.exe
Error: (11/06/2013 09:48:44 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Autodesk\Composite 2013\python\lib\distutils\command\wininst-8_d.exe
Error: (11/06/2013 09:25:10 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Autodesk\Composite 2013\python\lib\distutils\command\wininst-8_d.exe
Error: (11/02/2013 02:01:38 PM) (Source: Application Error)(User: )
Description: svchost.exe6.1.7600.163854a5bc3c1ntdll.dll6.1.7601.18247521eaf24c00000050000000000016eef38801ced7b05e723d73C:\Windows\system32\svchost.exeC:\Windows\SYSTEM32\ntdll.dlle89a8036-43be-11e3-b585-dc0ea11fc0a2
Error: (11/01/2013 04:33:50 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC80.DebugCRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"C:\Program Files\Autodesk\Composite 2013\python\lib\distutils\command\wininst-8_d.exe
==================== Memory info ===========================
Percentage of memory in use: 46%
Total physical RAM: 3947.86 MB
Available physical RAM: 2092.77 MB
Total Pagefile: 7893.9 MB
Available Pagefile: 5665.71 MB
Total Virtual: 8192 MB
Available Virtual: 8191.79 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:111.69 GB) (Free:54.96 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 0840D44F)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Gmer Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-11-14 13:34:37
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 KINGSTON rev.505A 111,79GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\ALEXAN~1\AppData\Local\Temp\awayauow.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002bb2000 45 bytes [00, 00, 00, 00, 00, 00, 00, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff80002bb202f 16 bytes [00, 00, 10, 00, 00, 00, 00, ...]
---- User code sections - GMER 2.1 ----
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\kernel32.dll!RegSetValueExW 00000000777aaf40 7 bytes JMP 000000016fff0260
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\kernel32.dll!RegQueryValueExW 00000000777b4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\kernel32.dll!RegDeleteValueW 00000000777d2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000777defe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000778099b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000778194d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077819640 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007783a500 7 bytes JMP 000000016fff0228
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdb32db0 5 bytes JMP 000007fffdae0180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdb337d0 7 bytes JMP 000007fffdae00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdb38ef0 6 bytes JMP 000007fffdae0148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdb4af60 5 bytes JMP 000007fffdae0110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd389e0 8 bytes JMP 000007fffdae01f0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd3be40 8 bytes JMP 000007fffdae01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe957490 11 bytes JMP 000007fffdae0228
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1172] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe96bf00 7 bytes JMP 000007fffdae0260
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\kernel32.dll!RegSetValueExW 00000000777aaf40 7 bytes JMP 000000016fff0260
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\kernel32.dll!RegQueryValueExW 00000000777b4a60 5 bytes JMP 000000016fff01b8
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\kernel32.dll!RegDeleteValueW 00000000777d2990 5 bytes JMP 000000016fff01f0
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000777defe0 5 bytes JMP 000000016fff0148
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000778099b0 7 bytes JMP 000000016fff00d8
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000778194d0 5 bytes JMP 000000016fff0180
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077819640 5 bytes JMP 000000016fff0110
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007783a500 7 bytes JMP 000000016fff0228
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdb32db0 5 bytes JMP 000007fffdae0180
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdb337d0 7 bytes JMP 000007fffdae00d8
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdb38ef0 6 bytes JMP 000007fffdae0148
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdb4af60 5 bytes JMP 000007fffdae0110
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd389e0 8 bytes JMP 000007fffdae01f0
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd3be40 8 bytes JMP 000007fffdae01b8
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\dxgi.dll!CreateDXGIFactory 000007fefa15dc88 5 bytes JMP 000007fff9f500d8
.text C:\Windows\system32\Dwm.exe[1388] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1 000007fefa15de10 5 bytes JMP 000007fff9f50110
.text C:\Windows\Explorer.EXE[1416] C:\Windows\system32\kernel32.dll!CopyFileExW 00000000777b23d0 5 bytes JMP 000000016fff00d8
.text C:\Windows\Explorer.EXE[1416] C:\Windows\system32\kernel32.dll!MoveFileWithProgressW 000000007782f6c0 8 bytes JMP 000000016fff0110
.text C:\Windows\Explorer.EXE[1416] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe957490 11 bytes JMP 000007fffe8f00d8
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\kernel32.dll!RegSetValueExW 00000000777aaf40 7 bytes JMP 000000016fff0260
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\kernel32.dll!RegQueryValueExW 00000000777b4a60 5 bytes JMP 000000016fff01b8
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\kernel32.dll!RegDeleteValueW 00000000777d2990 5 bytes JMP 000000016fff01f0
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000777defe0 5 bytes JMP 000000016fff0148
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000778099b0 7 bytes JMP 000000016fff00d8
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000778194d0 5 bytes JMP 000000016fff0180
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077819640 5 bytes JMP 000000016fff0110
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007783a500 7 bytes JMP 000000016fff0228
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdb32db0 5 bytes JMP 000007fffdae0180
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdb337d0 7 bytes JMP 000007fffdae00d8
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdb38ef0 6 bytes JMP 000007fffdae0148
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdb4af60 5 bytes JMP 000007fffdae0110
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd389e0 8 bytes JMP 000007fffdae01f0
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd3be40 8 bytes JMP 000007fffdae01b8
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe957490 11 bytes JMP 000007fffdae0228
.text C:\Windows\System32\igfxpers.exe[2088] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe96bf00 7 bytes JMP 000007fffdae0260
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\kernel32.dll!RegSetValueExW 00000000777aaf40 7 bytes JMP 000000016fff0260
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\kernel32.dll!RegQueryValueExW 00000000777b4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\kernel32.dll!RegDeleteValueW 00000000777d2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000777defe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000778099b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000778194d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077819640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007783a500 7 bytes JMP 000000016fff0228
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdb32db0 5 bytes JMP 000007fffdae0180
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdb337d0 7 bytes JMP 000007fffdae00d8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdb38ef0 6 bytes JMP 000007fffdae0148
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdb4af60 5 bytes JMP 000007fffdae0110
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd389e0 8 bytes JMP 000007fffdae01f0
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd3be40 8 bytes JMP 000007fffdae01b8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe957490 11 bytes JMP 000007fffdae0228
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[2164] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe96bf00 7 bytes JMP 000007fffdae0260
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000761f1eee 7 bytes JMP 0000000170b8168b
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000761f5b85 3 bytes JMP 0000000170b811a4
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\kernel32.dll!RegSetValueExW + 4 00000000761f5b89 3 bytes [FA, CC, CC]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000762013e1 7 bytes JMP 0000000170b81280
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 000000007620ea0d 7 bytes JMP 0000000170b8123a
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007621b1d3 5 bytes JMP 0000000170b815a0
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000762988b4 7 bytes JMP 0000000170b8132f
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076298939 5 bytes JMP 0000000170b816cc
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076298c8f 5 bytes JMP 0000000170b81703
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075a31d1b 5 bytes JMP 0000000170b811bd
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075a31dc9 5 bytes JMP 0000000170b81014
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075a32aa4 5 bytes JMP 0000000170b8154b
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075a32d0a 5 bytes JMP 0000000170b81267
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007679e96b 5 bytes JMP 0000000170b815b9
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007679eba5 5 bytes JMP 0000000170b81181
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076318a29 5 bytes JMP 0000000170b8171c
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076324572 5 bytes JMP 0000000170b810a0
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007633e567 5 bytes JMP 0000000170b8140b
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000076377a5c 5 bytes JMP 0000000170b815c8
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076935ea5 5 bytes JMP 0000000170b815f0
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076969d0b 5 bytes JMP 0000000170b81217
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe[2388] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2608] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
.text C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[2680] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe[2680] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000761f1eee 7 bytes JMP 0000000170b8168b
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000761f5b85 3 bytes JMP 0000000170b811a4
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\kernel32.dll!RegSetValueExW + 4 00000000761f5b89 3 bytes [FA, CC, CC]
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000762013e1 7 bytes JMP 0000000170b81280
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 000000007620ea0d 7 bytes JMP 0000000170b8123a
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007621b1d3 5 bytes JMP 0000000170b815a0
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000762988b4 7 bytes JMP 0000000170b8132f
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076298939 5 bytes JMP 0000000170b816cc
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076298c8f 5 bytes JMP 0000000170b81703
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075a31d1b 5 bytes JMP 0000000170b811bd
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075a31dc9 5 bytes JMP 0000000170b81014
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075a32aa4 5 bytes JMP 0000000170b8154b
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075a32d0a 5 bytes JMP 0000000170b81267
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076318a29 5 bytes JMP 0000000170b8171c
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076324572 5 bytes JMP 0000000170b810a0
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007633e567 5 bytes JMP 0000000170b8140b
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000076377a5c 5 bytes JMP 0000000170b815c8
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007679e96b 5 bytes JMP 0000000170b815b9
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007679eba5 5 bytes JMP 0000000170b81181
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076935ea5 5 bytes JMP 0000000170b815f0
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2760] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076969d0b 5 bytes JMP 0000000170b81217
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\kernel32.dll!RegSetValueExW 00000000777aaf40 7 bytes JMP 000000016fff0260
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\kernel32.dll!RegQueryValueExW 00000000777b4a60 5 bytes JMP 000000016fff01b8
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\kernel32.dll!RegDeleteValueW 00000000777d2990 5 bytes JMP 000000016fff01f0
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000777defe0 5 bytes JMP 000000016fff0148
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000778099b0 7 bytes JMP 000000016fff00d8
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000778194d0 5 bytes JMP 000000016fff0180
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077819640 5 bytes JMP 000000016fff0110
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007783a500 7 bytes JMP 000000016fff0228
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdb32db0 5 bytes JMP 000007fffdae0180
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdb337d0 7 bytes JMP 000007fffdae00d8
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdb38ef0 6 bytes JMP 000007fffdae0148
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdb4af60 5 bytes JMP 000007fffdae0110
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd389e0 8 bytes JMP 000007fffdae01f0
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd3be40 8 bytes JMP 000007fffdae01b8
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe957490 11 bytes JMP 000007fffdae0228
.text C:\Windows\System32\wscript.exe[2772] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe96bf00 7 bytes JMP 000007fffdae0260
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2812] C:\Windows\system32\kernel32.dll!RegSetValueExW 00000000777aaf40 7 bytes JMP 000000016fff0260
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2812] C:\Windows\system32\kernel32.dll!RegQueryValueExW 00000000777b4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2812] C:\Windows\system32\kernel32.dll!RegDeleteValueW 00000000777d2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2812] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000777defe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2812] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000778099b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2812] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000778194d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2812] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077819640 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2812] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007783a500 7 bytes JMP 000000016fff0228
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2812] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdb32db0 5 bytes JMP 000007fffdae0180
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2812] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdb337d0 7 bytes JMP 000007fffdae00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2812] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdb38ef0 6 bytes JMP 000007fffdae0148
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2812] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdb4af60 5 bytes JMP 000007fffdae0110
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2812] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd389e0 8 bytes JMP 000007fffdae01f0
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2812] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd3be40 8 bytes JMP 000007fffdae01b8
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000761f1eee 7 bytes JMP 0000000170b8168b
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000761f5b85 3 bytes JMP 0000000170b811a4
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\kernel32.dll!RegSetValueExW + 4 00000000761f5b89 3 bytes [FA, CC, CC]
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000762013e1 7 bytes JMP 0000000170b81280
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 000000007620ea0d 7 bytes JMP 0000000170b8123a
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007621b1d3 5 bytes JMP 0000000170b815a0
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000762988b4 7 bytes JMP 0000000170b8132f
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076298939 5 bytes JMP 0000000170b816cc
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076298c8f 5 bytes JMP 0000000170b81703
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075a31d1b 5 bytes JMP 0000000170b811bd
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075a31dc9 5 bytes JMP 0000000170b81014
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075a32aa4 5 bytes JMP 0000000170b8154b
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075a32d0a 5 bytes JMP 0000000170b81267
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076318a29 5 bytes JMP 0000000170b8171c
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076324572 5 bytes JMP 0000000170b810a0
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007633e567 5 bytes JMP 0000000170b8140b
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000076377a5c 5 bytes JMP 0000000170b815c8
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007679e96b 5 bytes JMP 0000000170b815b9
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007679eba5 5 bytes JMP 0000000170b81181
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076935ea5 5 bytes JMP 0000000170b815f0
.text C:\Users\Alexander\AppData\Local\Akamai\netsession_win.exe[2852] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076969d0b 5 bytes JMP 0000000170b81217
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW 00000000761f1eee 7 bytes JMP 0000000170b8168b
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW 00000000761f5b85 3 bytes JMP 0000000170b811a4
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW + 4 00000000761f5b89 3 bytes [FA, CC, CC]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA 00000000762013e1 7 bytes JMP 0000000170b81280
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW 000000007620ea0d 7 bytes JMP 0000000170b8123a
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleFileNameExW 000000007621b1d3 5 bytes JMP 0000000170b815a0
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx 00000000762988b4 7 bytes JMP 0000000170b8132f
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation 0000000076298939 5 bytes JMP 0000000170b816cc
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW 0000000076298c8f 5 bytes JMP 0000000170b81703
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075a31d1b 5 bytes JMP 0000000170b811bd
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075a31dc9 5 bytes JMP 0000000170b81014
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075a32aa4 5 bytes JMP 0000000170b8154b
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075a32d0a 5 bytes JMP 0000000170b81267
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007679e96b 5 bytes JMP 0000000170b815b9
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007679eba5 5 bytes JMP 0000000170b81181
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076318a29 5 bytes JMP 0000000170b8171c
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076324572 5 bytes JMP 0000000170b810a0
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007633e567 5 bytes JMP 0000000170b8140b
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000076377a5c 5 bytes JMP 0000000170b815c8
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076935ea5 5 bytes JMP 0000000170b815f0
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076969d0b 5 bytes JMP 0000000170b81217
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[2920] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000761f1eee 7 bytes JMP 0000000170b8168b
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000761f5b85 3 bytes JMP 0000000170b811a4
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\kernel32.dll!RegSetValueExW + 4 00000000761f5b89 3 bytes [FA, CC, CC]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000762013e1 7 bytes JMP 0000000170b81280
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 000000007620ea0d 7 bytes JMP 0000000170b8123a
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007621b1d3 5 bytes JMP 0000000170b815a0
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000762988b4 7 bytes JMP 0000000170b8132f
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076298939 5 bytes JMP 0000000170b816cc
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076298c8f 5 bytes JMP 0000000170b81703
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075a31d1b 5 bytes JMP 0000000170b811bd
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075a31dc9 5 bytes JMP 0000000170b81014
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075a32aa4 5 bytes JMP 0000000170b8154b
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075a32d0a 5 bytes JMP 0000000170b81267
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007679e96b 5 bytes JMP 0000000170b815b9
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007679eba5 5 bytes JMP 0000000170b81181
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076318a29 5 bytes JMP 0000000170b8171c
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076324572 5 bytes JMP 0000000170b810a0
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007633e567 5 bytes JMP 0000000170b8140b
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000076377a5c 5 bytes JMP 0000000170b815c8
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076935ea5 5 bytes JMP 0000000170b815f0
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076969d0b 5 bytes JMP 0000000170b81217
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[2928] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000761f1eee 7 bytes JMP 0000000170b8168b
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000761f5b85 3 bytes JMP 0000000170b811a4
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\kernel32.dll!RegSetValueExW + 4 00000000761f5b89 3 bytes [FA, CC, CC]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000762013e1 7 bytes JMP 0000000170b81280
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 000000007620ea0d 7 bytes JMP 0000000170b8123a
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007621b1d3 5 bytes JMP 0000000170b815a0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000762988b4 7 bytes JMP 0000000170b8132f
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076298939 5 bytes JMP 0000000170b816cc
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076298c8f 5 bytes JMP 0000000170b81703
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075a31d1b 5 bytes JMP 0000000170b811bd
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075a31dc9 5 bytes JMP 0000000170b81014
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075a32aa4 5 bytes JMP 0000000170b8154b
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075a32d0a 5 bytes JMP 0000000170b81267
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007679e96b 5 bytes JMP 0000000170b815b9
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007679eba5 5 bytes JMP 0000000170b81181
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076318a29 5 bytes JMP 0000000170b8171c
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076324572 5 bytes JMP 0000000170b810a0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007633e567 5 bytes JMP 0000000170b8140b
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000076377a5c 5 bytes JMP 0000000170b815c8
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076935ea5 5 bytes JMP 0000000170b815f0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076969d0b 5 bytes JMP 0000000170b81217
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3064] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
.text C:\Program Files\Autodesk\3ds Max 2013\NVIDIA\raysat_3dsmax2013_64server.exe[1148] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Program Files\Autodesk\3ds Max 2013\NVIDIA\raysat_3dsmax2013_64server.exe[1148] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[3480] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe[3480] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\kernel32.dll!RegSetValueExW 00000000777aaf40 7 bytes JMP 000000016fff0260
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\kernel32.dll!RegQueryValueExW 00000000777b4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\kernel32.dll!RegDeleteValueW 00000000777d2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000777defe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000778099b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000778194d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077819640 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007783a500 7 bytes JMP 000000016fff0228
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdb32db0 5 bytes JMP 000007fffdae0180
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdb337d0 7 bytes JMP 000007fffdae00d8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdb38ef0 6 bytes JMP 000007fffdae0148
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdb4af60 5 bytes JMP 000007fffdae0110
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd389e0 8 bytes JMP 000007fffdae01f0
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd3be40 8 bytes JMP 000007fffdae01b8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\d3d9.dll!Direct3DCreate9Ex 000007fef5792460 4 bytes JMP 000007fefdae02d0
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4068] C:\Windows\system32\d3d9.dll!Direct3DCreate9 000007fef57c96b0 6 bytes JMP 000007fefdae0298
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4956] C:\Windows\system32\kernel32.dll!RegSetValueExW 00000000777aaf40 7 bytes JMP 000000016fff0260
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4956] C:\Windows\system32\kernel32.dll!RegQueryValueExW 00000000777b4a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4956] C:\Windows\system32\kernel32.dll!RegDeleteValueW 00000000777d2990 5 bytes JMP 000000016fff01f0
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4956] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000777defe0 5 bytes JMP 000000016fff0148
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4956] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000778099b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4956] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000778194d0 5 bytes JMP 000000016fff0180
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4956] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077819640 5 bytes JMP 000000016fff0110
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4956] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007783a500 7 bytes JMP 000000016fff0228
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4956] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdb32db0 5 bytes JMP 000007fffdae0180
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4956] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdb337d0 7 bytes JMP 000007fffdae00d8
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4956] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdb38ef0 6 bytes JMP 000007fffdae0148
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4956] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdb4af60 5 bytes JMP 000007fffdae0110
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4956] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd389e0 8 bytes JMP 000007fffdae01f0
.text C:\Program Files\Synaptics\SynTP\SynTPHelper.exe[4956] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd3be40 8 bytes JMP 000007fffdae01b8
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5636] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[5636] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\kernel32.dll!RegSetValueExW 00000000777aaf40 7 bytes JMP 000000016fff0260
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\kernel32.dll!RegQueryValueExW 00000000777b4a60 5 bytes JMP 000000016fff01b8
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\kernel32.dll!RegDeleteValueW 00000000777d2990 5 bytes JMP 000000016fff01f0
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 00000000777defe0 5 bytes JMP 000000016fff0148
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 00000000778099b0 7 bytes JMP 000000016fff00d8
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 00000000778194d0 5 bytes JMP 000000016fff0180
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000077819640 5 bytes JMP 000000016fff0110
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\kernel32.dll!RegSetValueExA 000000007783a500 7 bytes JMP 000000016fff0228
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefdb32db0 5 bytes JMP 000007fffdae0180
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefdb337d0 7 bytes JMP 000007fffdae00d8
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefdb38ef0 6 bytes JMP 000007fffdae0148
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefdb4af60 5 bytes JMP 000007fffdae0110
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd389e0 8 bytes JMP 000007fffdae01f0
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd3be40 8 bytes JMP 000007fffdae01b8
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe957490 11 bytes JMP 000007fffdae0228
.text C:\Windows\system32\taskmgr.exe[4932] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe96bf00 7 bytes JMP 000007fffdae0260
.text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[6108] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe[6108] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
.text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[5028] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe[5028] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
.text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[4944] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe[4944] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000761f1eee 7 bytes JMP 0000000170b8168b
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000761f5b85 3 bytes JMP 0000000170b811a4
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\kernel32.dll!RegSetValueExW + 4 00000000761f5b89 3 bytes [FA, CC, CC]
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000762013e1 7 bytes JMP 0000000170b81280
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 000000007620ea0d 7 bytes JMP 0000000170b8123a
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 000000007621b1d3 5 bytes JMP 0000000170b815a0
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000762988b4 7 bytes JMP 0000000170b8132f
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076298939 5 bytes JMP 0000000170b816cc
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076298c8f 5 bytes JMP 0000000170b81703
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075a31d1b 5 bytes JMP 0000000170b811bd
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075a31dc9 5 bytes JMP 0000000170b81014
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075a32aa4 5 bytes JMP 0000000170b8154b
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075a32d0a 5 bytes JMP 0000000170b81267
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007679e96b 5 bytes JMP 0000000170b815b9
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007679eba5 5 bytes JMP 0000000170b81181
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000076318a29 5 bytes JMP 0000000170b8171c
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000076324572 5 bytes JMP 0000000170b810a0
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 000000007633e567 5 bytes JMP 0000000170b8140b
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000076377a5c 5 bytes JMP 0000000170b815c8
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076935ea5 5 bytes JMP 0000000170b815f0
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076969d0b 5 bytes JMP 0000000170b81217
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076401465 2 bytes [40, 76]
.text C:\Users\Alexander\Desktop\gmer_2.1.19163.exe[1716] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000764014bb 2 bytes [40, 76]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5832:3044] 000007fefbaf2a7c
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5832:3368] 000007fef01ed618
Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [5832:4472] 000007fef6905124
---- EOF - GMER 2.1 ---- |