GMER.txt: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-07-21 12:35:55
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST500LM000-SSHD-8GB rev.LIV5 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\Chris\AppData\Local\Temp\kglyapow.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007760a3e0 7 bytes JMP 000000016fff0228
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077613f00 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007762ffd0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763f350 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077669aa0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077679530 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077698850 7 bytes JMP 000000016fff01f0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe4874a0 11 bytes JMP 000007fffd730228
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2868] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe49bf10 7 bytes JMP 000007fffd730260
.text C:\Windows\system32\Dwm.exe[2956] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Windows\system32\Dwm.exe[2956] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Windows\system32\Dwm.exe[2956] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Windows\system32\Dwm.exe[2956] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Windows\system32\Dwm.exe[2956] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Windows\system32\Dwm.exe[2956] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Windows\system32\Dwm.exe[2956] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Windows\system32\Dwm.exe[2956] C:\Windows\system32\dxgi.dll!CreateDXGIFactory 000007fef6aadc88 5 bytes JMP 000007fff6a800d8
.text C:\Windows\system32\Dwm.exe[2956] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1 000007fef6aade10 5 bytes JMP 000007fff6a80110
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000772a1efe 7 bytes JMP 0000000173693d10
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000772a5b9d 7 bytes JMP 00000001736946b0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000772b13f9 7 bytes JMP 0000000173694050
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000772bea45 7 bytes JMP 0000000173693d00
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000077348ea4 7 bytes JMP 00000001736937c0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000077348f29 5 bytes JMP 0000000173693870
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000077349281 5 bytes JMP 00000001736937d0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770f1d29 5 bytes JMP 0000000173693780
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770f1dd7 5 bytes JMP 0000000173693740
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770f2ab1 5 bytes JMP 0000000173693880
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770f2d1d 5 bytes JMP 0000000173693560
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\USER32.dll!CreateWindowExW 00000000771a8a29 5 bytes JMP 0000000173692c50
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 00000000771b4572 5 bytes JMP 00000001736934e0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000771ce567 5 bytes JMP 0000000173693550
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000771f07d7 5 bytes JMP 0000000173692a60
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000077207a5c 5 bytes JMP 00000001736934d0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076fad2b4 5 bytes JMP 0000000173692d70
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076fad4ee 5 bytes JMP 0000000173692d80
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 00000000774b5ea5 5 bytes JMP 0000000173692c10
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000774e9d0b 5 bytes JMP 0000000173692ba0
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000767e1401 2 bytes JMP 772cb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000767e1419 2 bytes JMP 772cb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000767e1431 2 bytes JMP 77348f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000767e144a 2 bytes CALL 772a489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000767e14dd 2 bytes JMP 77348822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000767e14f5 2 bytes JMP 773489f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000767e150d 2 bytes JMP 77348718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000767e1525 2 bytes JMP 77348ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000767e153d 2 bytes JMP 772bfca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000767e1555 2 bytes JMP 772c68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000767e156d 2 bytes JMP 77348fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000767e1585 2 bytes JMP 77348b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000767e159d 2 bytes JMP 773486dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000767e15b5 2 bytes JMP 772bfd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000767e15cd 2 bytes JMP 772cb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000767e16b2 2 bytes JMP 77348ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3512] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000767e16bd 2 bytes JMP 77348671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007760a3e0 7 bytes JMP 000000016fff0228
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077613f00 5 bytes JMP 000000016fff0180
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007762ffd0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763f350 5 bytes JMP 000000016fff0110
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077669aa0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077679530 5 bytes JMP 000000016fff0148
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077698850 7 bytes JMP 000000016fff01f0
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3544] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007760a3e0 7 bytes JMP 000000016fff0228
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077613f00 5 bytes JMP 000000016fff0180
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007762ffd0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763f350 5 bytes JMP 000000016fff0110
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077669aa0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077679530 5 bytes JMP 000000016fff0148
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077698850 7 bytes JMP 000000016fff01f0
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe4874a0 11 bytes JMP 000007fffd730228
.text C:\Program Files\Elantech\ETDCtrl.exe[3588] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe49bf10 7 bytes JMP 000007fffd730260
.text C:\Windows\System32\igfxpers.exe[3720] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Windows\System32\igfxpers.exe[3720] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Windows\System32\igfxpers.exe[3720] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Windows\System32\igfxpers.exe[3720] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Windows\System32\igfxpers.exe[3720] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Windows\System32\igfxpers.exe[3720] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Windows\System32\igfxpers.exe[3720] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Windows\System32\igfxpers.exe[3720] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe4874a0 11 bytes JMP 000007fffd730228
.text C:\Windows\System32\igfxpers.exe[3720] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe49bf10 7 bytes JMP 000007fffd730260
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000772a1efe 7 bytes JMP 0000000173693d10
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000772a5b9d 7 bytes JMP 00000001736946b0
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000772b13f9 7 bytes JMP 0000000173694050
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000772bea45 7 bytes JMP 0000000173693d00
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000077348ea4 7 bytes JMP 00000001736937c0
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000077348f29 5 bytes JMP 0000000173693870
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000077349281 5 bytes JMP 00000001736937d0
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770f1d29 5 bytes JMP 0000000173693780
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770f1dd7 5 bytes JMP 0000000173693740
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770f2ab1 5 bytes JMP 0000000173693880
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770f2d1d 5 bytes JMP 0000000173693560
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\USER32.dll!CreateWindowExW 00000000771a8a29 5 bytes JMP 0000000173692c50
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 00000000771b4572 5 bytes JMP 00000001736934e0
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000771ce567 5 bytes JMP 0000000173693550
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000771f07d7 5 bytes JMP 0000000173692a60
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000077207a5c 5 bytes JMP 00000001736934d0
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076fad2b4 5 bytes JMP 0000000173692d70
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076fad4ee 5 bytes JMP 0000000173692d80
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 00000000774b5ea5 5 bytes JMP 0000000173692c10
.text C:\Windows\vsnp2uvc.exe[3828] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000774e9d0b 5 bytes JMP 0000000173692ba0
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000772a1efe 7 bytes JMP 0000000173693d10
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000772a5b9d 7 bytes JMP 00000001736946b0
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000772a8781 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000772b13f9 7 bytes JMP 0000000173694050
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000772bea45 7 bytes JMP 0000000173693d00
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000077348ea4 7 bytes JMP 00000001736937c0
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000077348f29 5 bytes JMP 0000000173693870
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000077349281 5 bytes JMP 00000001736937d0
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770f1d29 5 bytes JMP 0000000173693780
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770f1dd7 5 bytes JMP 0000000173693740
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770f2ab1 5 bytes JMP 0000000173693880
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770f2d1d 5 bytes JMP 0000000173693560
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\USER32.dll!CreateWindowExW 00000000771a8a29 5 bytes JMP 0000000173692c50
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 00000000771b4572 5 bytes JMP 00000001736934e0
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000771ce567 5 bytes JMP 0000000173693550
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000771f07d7 5 bytes JMP 0000000173692a60
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000077207a5c 5 bytes JMP 00000001736934d0
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076fad2b4 5 bytes JMP 0000000173692d70
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076fad4ee 5 bytes JMP 0000000173692d80
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000767e1401 2 bytes JMP 772cb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000767e1419 2 bytes JMP 772cb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000767e1431 2 bytes JMP 77348f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000767e144a 2 bytes CALL 772a489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000767e14dd 2 bytes JMP 77348822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000767e14f5 2 bytes JMP 773489f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000767e150d 2 bytes JMP 77348718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000767e1525 2 bytes JMP 77348ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000767e153d 2 bytes JMP 772bfca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000767e1555 2 bytes JMP 772c68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000767e156d 2 bytes JMP 77348fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000767e1585 2 bytes JMP 77348b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000767e159d 2 bytes JMP 773486dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000767e15b5 2 bytes JMP 772bfd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000767e15cd 2 bytes JMP 772cb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000767e16b2 2 bytes JMP 77348ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3892] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000767e16bd 2 bytes JMP 77348671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000772a1efe 7 bytes JMP 0000000173693d10
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000772a5b9d 7 bytes JMP 00000001736946b0
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000772b13f9 7 bytes JMP 0000000173694050
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000772bea45 7 bytes JMP 0000000173693d00
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000077348ea4 7 bytes JMP 00000001736937c0
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000077348f29 5 bytes JMP 0000000173693870
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000077349281 5 bytes JMP 00000001736937d0
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770f1d29 5 bytes JMP 0000000173693780
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770f1dd7 5 bytes JMP 0000000173693740
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770f2ab1 5 bytes JMP 0000000173693880
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770f2d1d 5 bytes JMP 0000000173693560
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\USER32.dll!CreateWindowExW 00000000771a8a29 5 bytes JMP 0000000173692c50
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 00000000771b4572 5 bytes JMP 00000001736934e0
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000771ce567 5 bytes JMP 0000000173693550
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000771f07d7 5 bytes JMP 0000000173692a60
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000077207a5c 5 bytes JMP 00000001736934d0
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076fad2b4 5 bytes JMP 0000000173692d70
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076fad4ee 5 bytes JMP 0000000173692d80
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 00000000774b5ea5 5 bytes JMP 0000000173692c10
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\ole32.dll!CoCreateInstance 00000000774e9d0b 5 bytes JMP 0000000173692ba0
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000767e1401 2 bytes JMP 772cb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000767e1419 2 bytes JMP 772cb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000767e1431 2 bytes JMP 77348f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000767e144a 2 bytes CALL 772a489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000767e14dd 2 bytes JMP 77348822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000767e14f5 2 bytes JMP 773489f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000767e150d 2 bytes JMP 77348718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000767e1525 2 bytes JMP 77348ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000767e153d 2 bytes JMP 772bfca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000767e1555 2 bytes JMP 772c68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000767e156d 2 bytes JMP 77348fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000767e1585 2 bytes JMP 77348b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000767e159d 2 bytes JMP 773486dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000767e15b5 2 bytes JMP 772bfd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000767e15cd 2 bytes JMP 772cb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000767e16b2 2 bytes JMP 77348ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe[3932] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000767e16bd 2 bytes JMP 77348671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[3180] C:\Windows\system32\kernel32.dll!RegSetValueExW 000000007760a3e0 7 bytes JMP 000000016fff0228
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[3180] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000077613f00 5 bytes JMP 000000016fff0180
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[3180] C:\Windows\system32\kernel32.dll!RegDeleteValueW 000000007762ffd0 5 bytes JMP 000000016fff01b8
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[3180] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 000000007763f350 5 bytes JMP 000000016fff0110
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[3180] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000077669aa0 7 bytes JMP 000000016fff00d8
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[3180] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000077679530 5 bytes JMP 000000016fff0148
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[3180] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000077698850 7 bytes JMP 000000016fff01f0
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[3180] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[3180] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[3180] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[3180] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[3180] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[3180] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Program Files\Elantech\ETDCtrlHelper.exe[3180] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Windows\system32\wbem\unsecapp.exe[1956] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Windows\system32\wbem\unsecapp.exe[1956] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Windows\system32\wbem\unsecapp.exe[1956] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Windows\system32\wbem\unsecapp.exe[1956] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Windows\system32\wbem\unsecapp.exe[1956] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Windows\system32\wbem\unsecapp.exe[1956] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe4874a0 11 bytes JMP 000007fffd730228
.text C:\Windows\system32\wbem\unsecapp.exe[1956] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe49bf10 7 bytes JMP 000007fffd730260
.text C:\Windows\system32\wbem\unsecapp.exe[1956] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Windows\system32\wbem\unsecapp.exe[1956] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077843260 5 bytes JMP 00000001003d075c
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077846f30 5 bytes JMP 00000001003d03a4
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 000000007786de30 16 bytes [50, 48, B8, 30, 35, B2, EF, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\KERNEL32.dll!RegSetValueExW 000000007760a3e0 7 bytes JMP 000000016fff0228
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW 0000000077613f00 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW 000000007762ffd0 5 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 000000007763f350 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 0000000077669aa0 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 0000000077679530 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 0000000077698850 7 bytes JMP 000000016fff01f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 0000000077726c80 5 bytes JMP 000000016fff02d0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000000007772a5b4 5 bytes JMP 000000016fff0298
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\USER32.dll!CreateWindowExW 0000000077730810 7 bytes JMP 000000016fff0308
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000000007773ccec 9 bytes JMP 000000016fff0260
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 0000000077770700 5 bytes JMP 000000016fff0340
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe4874a0 11 bytes JMP 000007fffd730228
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3764] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe49bf10 7 bytes JMP 000007fffd730260
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077843260 5 bytes JMP 000000010027075c
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077846f30 5 bytes JMP 00000001002703a4
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007786dc80 16 bytes [50, 48, B8, 90, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 000000007786ddf0 16 bytes [50, 48, B8, E8, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007786de10 48 bytes [50, 48, B8, 64, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 000000007786de50 16 bytes [50, 48, B8, B4, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 000000007786dea0 32 bytes [50, 48, B8, 0C, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 000000007786dee0 16 bytes [50, 48, B8, F4, E8, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 000000007786df80 16 bytes [50, 48, B8, 3C, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 000000007786e100 3 bytes [50, 48, B8]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 4 000000007786e104 12 bytes [E7, 1C, 3F, 01, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 000000007786eb70 16 bytes [50, 48, B8, 88, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007786ebc0 16 bytes [50, 48, B8, C4, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 000000007786ed10 16 bytes [50, 48, B8, 50, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\system32\KERNEL32.dll!RegSetValueExW 000000007760a3e0 7 bytes JMP 000000016fff0228
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW 0000000077613f00 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW 000000007762ffd0 5 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 000000007763f350 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 0000000077669aa0 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 0000000077679530 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 0000000077698850 7 bytes JMP 000000016fff01f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4252] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077843260 5 bytes JMP 00000001002e075c
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077846f30 5 bytes JMP 00000001002e03a4
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007786dc80 16 bytes [50, 48, B8, 90, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 000000007786ddf0 16 bytes [50, 48, B8, E8, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007786de10 48 bytes [50, 48, B8, 64, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 000000007786de50 16 bytes [50, 48, B8, B4, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 000000007786dea0 32 bytes [50, 48, B8, 0C, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 000000007786dee0 16 bytes [50, 48, B8, F4, E8, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 000000007786df80 16 bytes [50, 48, B8, 3C, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 000000007786e100 3 bytes [50, 48, B8]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 4 000000007786e104 12 bytes [E7, 1C, 3F, 01, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 000000007786eb70 16 bytes [50, 48, B8, 88, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007786ebc0 16 bytes [50, 48, B8, C4, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 000000007786ed10 16 bytes [50, 48, B8, 50, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\system32\KERNEL32.dll!RegSetValueExW 000000007760a3e0 7 bytes JMP 000000016fff0228
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW 0000000077613f00 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW 000000007762ffd0 5 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 000000007763f350 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 0000000077669aa0 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 0000000077679530 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 0000000077698850 7 bytes JMP 000000016fff01f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4416] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077843260 5 bytes JMP 000000010023075c
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077846f30 5 bytes JMP 00000001002303a4
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007786dc80 16 bytes [50, 48, B8, 90, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 000000007786ddf0 16 bytes [50, 48, B8, E8, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007786de10 48 bytes [50, 48, B8, 64, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 000000007786de50 16 bytes [50, 48, B8, B4, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 000000007786dea0 32 bytes [50, 48, B8, 0C, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 000000007786dee0 16 bytes [50, 48, B8, F4, E8, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 000000007786df80 16 bytes [50, 48, B8, 3C, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 000000007786e100 3 bytes [50, 48, B8]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 4 000000007786e104 12 bytes [E7, 1C, 3F, 01, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 000000007786eb70 16 bytes [50, 48, B8, 88, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007786ebc0 16 bytes [50, 48, B8, C4, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 000000007786ed10 16 bytes [50, 48, B8, 50, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\system32\KERNEL32.dll!RegSetValueExW 000000007760a3e0 7 bytes JMP 000000016fff0228
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW 0000000077613f00 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW 000000007762ffd0 5 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 000000007763f350 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 0000000077669aa0 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 0000000077679530 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 0000000077698850 7 bytes JMP 000000016fff01f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4512] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077843260 5 bytes JMP 00000001002c075c
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077846f30 5 bytes JMP 00000001002c03a4
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007786dc80 16 bytes [50, 48, B8, 90, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 000000007786ddf0 16 bytes [50, 48, B8, E8, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007786de10 48 bytes [50, 48, B8, 64, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 000000007786de50 16 bytes [50, 48, B8, B4, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 000000007786dea0 32 bytes [50, 48, B8, 0C, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 000000007786dee0 16 bytes [50, 48, B8, F4, E8, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 000000007786df80 16 bytes [50, 48, B8, 3C, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 000000007786e100 3 bytes [50, 48, B8]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 4 000000007786e104 12 bytes [E7, 1C, 3F, 01, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 000000007786eb70 16 bytes [50, 48, B8, 88, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007786ebc0 16 bytes [50, 48, B8, C4, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 000000007786ed10 16 bytes [50, 48, B8, 50, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\system32\KERNEL32.dll!RegSetValueExW 000000007760a3e0 7 bytes JMP 000000016fff0228
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW 0000000077613f00 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW 000000007762ffd0 5 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 000000007763f350 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 0000000077669aa0 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 0000000077679530 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 0000000077698850 7 bytes JMP 000000016fff01f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4564] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077843260 5 bytes JMP 00000001003f075c
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077846f30 5 bytes JMP 00000001003f03a4
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007786dc80 16 bytes [50, 48, B8, 90, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 000000007786ddf0 16 bytes [50, 48, B8, E8, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007786de10 48 bytes [50, 48, B8, 64, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 000000007786de50 16 bytes [50, 48, B8, B4, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 000000007786dea0 32 bytes [50, 48, B8, 0C, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 000000007786dee0 16 bytes [50, 48, B8, F4, E8, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 000000007786df80 16 bytes [50, 48, B8, 3C, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 000000007786e100 3 bytes [50, 48, B8]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 4 000000007786e104 12 bytes [E7, 1C, 3F, 01, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 000000007786eb70 16 bytes [50, 48, B8, 88, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007786ebc0 16 bytes [50, 48, B8, C4, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 000000007786ed10 16 bytes [50, 48, B8, 50, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\system32\KERNEL32.dll!RegSetValueExW 000000007760a3e0 7 bytes JMP 000000016fff0228
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW 0000000077613f00 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW 000000007762ffd0 5 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 000000007763f350 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 0000000077669aa0 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 0000000077679530 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 0000000077698850 7 bytes JMP 000000016fff01f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4852] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Windows\system32\wuauclt.exe[3972] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Windows\system32\wuauclt.exe[3972] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Windows\system32\wuauclt.exe[3972] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Windows\system32\wuauclt.exe[3972] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Windows\system32\wuauclt.exe[3972] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Windows\system32\wuauclt.exe[3972] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe4874a0 11 bytes JMP 000007fffd730228
.text C:\Windows\system32\wuauclt.exe[3972] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe49bf10 7 bytes JMP 000007fffd730260
.text C:\Windows\system32\wuauclt.exe[3972] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Windows\system32\wuauclt.exe[3972] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000772a1efe 7 bytes JMP 0000000173693d10
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000772a5b9d 7 bytes JMP 00000001736946b0
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000772a8781 5 bytes JMP 00000001684b68d3
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000772b13f9 7 bytes JMP 0000000173694050
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000772bea45 7 bytes JMP 0000000173693d00
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000077348ea4 7 bytes JMP 00000001736937c0
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000077348f29 5 bytes JMP 0000000173693870
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000077349281 5 bytes JMP 00000001736937d0
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770f1d29 5 bytes JMP 0000000173693780
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770f1dd7 5 bytes JMP 0000000173693740
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770f2ab1 5 bytes JMP 0000000173693880
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770f2d1d 5 bytes JMP 0000000173693560
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076fad2b4 5 bytes JMP 0000000173692d70
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076fad4ee 5 bytes JMP 0000000173692d80
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\USER32.dll!CreateWindowExW 00000000771a8a29 5 bytes JMP 0000000173692c50
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 00000000771b4572 5 bytes JMP 00000001736934e0
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000771ce567 5 bytes JMP 0000000173693550
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000771f07d7 5 bytes JMP 0000000173692a60
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000077207a5c 5 bytes JMP 00000001736934d0
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\ole32.dll!OleLoadFromStream 00000000774a6143 5 bytes JMP 00000001691adda2
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\OLEAUT32.dll!SysFreeString 0000000077023e59 5 bytes JMP 00000001688851ee
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\OLEAUT32.dll!VariantClear 0000000077023eae 5 bytes JMP 000000016888515f
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\OLEAUT32.dll!SysAllocStringByteLen 0000000077024731 5 bytes JMP 00000001687b8abb
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\OLEAUT32.dll!VariantChangeType 0000000077025dee 5 bytes JMP 000000016876e63e
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Program Files (x86)\Microsoft Office\Office14\BCSProxy32.dll!ReleaseMutex + 215 0000000069c62338 4 bytes [33, 02, FC, 8F]
? C:\Windows\system32\mssprxy.dll [4320] entry point in ".rdata" section 0000000071e571e6
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 00000000767e1401 2 bytes JMP 772cb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 00000000767e1419 2 bytes JMP 772cb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 00000000767e1431 2 bytes JMP 77348f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 00000000767e144a 2 bytes CALL 772a489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000767e14dd 2 bytes JMP 77348822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000767e14f5 2 bytes JMP 773489f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 00000000767e150d 2 bytes JMP 77348718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 00000000767e1525 2 bytes JMP 77348ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 00000000767e153d 2 bytes JMP 772bfca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 00000000767e1555 2 bytes JMP 772c68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 00000000767e156d 2 bytes JMP 77348fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 00000000767e1585 2 bytes JMP 77348b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 00000000767e159d 2 bytes JMP 773486dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000767e15b5 2 bytes JMP 772bfd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000767e15cd 2 bytes JMP 772cb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000767e16b2 2 bytes JMP 77348ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE[4320] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000767e16bd 2 bytes JMP 77348671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll 0000000077843260 5 bytes JMP 00000001002c075c
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll 0000000077846f30 5 bytes JMP 00000001002c03a4
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 000000007786dc80 16 bytes [50, 48, B8, 90, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 000000007786ddf0 16 bytes [50, 48, B8, E8, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007786de10 48 bytes [50, 48, B8, 64, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 000000007786de50 16 bytes [50, 48, B8, B4, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 000000007786dea0 32 bytes [50, 48, B8, 0C, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 000000007786dee0 16 bytes [50, 48, B8, F4, E8, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 000000007786df80 16 bytes [50, 48, B8, 3C, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 000000007786e100 3 bytes [50, 48, B8]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile + 4 000000007786e104 12 bytes [E7, 1C, 3F, 01, 00, 00, 00, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 000000007786eb70 16 bytes [50, 48, B8, 88, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007786ebc0 16 bytes [50, 48, B8, C4, E9, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 000000007786ed10 16 bytes [50, 48, B8, 50, EA, 1C, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\system32\KERNEL32.dll!RegSetValueExW 000000007760a3e0 7 bytes JMP 000000016fff0228
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW 0000000077613f00 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW 000000007762ffd0 5 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 000000007763f350 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 0000000077669aa0 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 0000000077679530 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 0000000077698850 7 bytes JMP 000000016fff01f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefd762db0 5 bytes JMP 000007fffd730180
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefd7637d0 7 bytes JMP 000007fffd7300d8
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefd76a410 2 bytes JMP 000007fffd730110
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW + 3 000007fefd76a413 2 bytes [FC, FF]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefd76aec0 6 bytes JMP 000007fffd730148
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefdd989d0 8 bytes JMP 000007fffd7301f0
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3140] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefdd9be40 8 bytes JMP 000007fffd7301b8
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000772a1efe 7 bytes JMP 0000000173693d10
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000772a5b9d 7 bytes JMP 00000001736946b0
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000772b13f9 7 bytes JMP 0000000173694050
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000772bea45 7 bytes JMP 0000000173693d00
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 0000000077348ea4 7 bytes JMP 00000001736937c0
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000077348f29 5 bytes JMP 0000000173693870
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000077349281 5 bytes JMP 00000001736937d0
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 00000000770f1d29 5 bytes JMP 0000000173693780
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 00000000770f1dd7 5 bytes JMP 0000000173693740
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 00000000770f2ab1 5 bytes JMP 0000000173693880
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 00000000770f2d1d 5 bytes JMP 0000000173693560
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 0000000076fad2b4 5 bytes JMP 0000000173692d70
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 0000000076fad4ee 5 bytes JMP 0000000173692d80
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\USER32.dll!CreateWindowExW 00000000771a8a29 5 bytes JMP 0000000173692c50
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 00000000771b4572 5 bytes JMP 00000001736934e0
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 00000000771ce567 5 bytes JMP 0000000173693550
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 00000000771f07d7 5 bytes JMP 0000000173692a60
.text C:\Users\Chris\Desktop\Gmer-19357.exe[4460] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000077207a5c 5 bytes JMP 00000001736934d0
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [5092:2532] 000007fee5c69688
---- EOF - GMER 2.1 ---- |