GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-05-24 23:13:12
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD50 rev.01.0 465,76GB
Running: q52uzqrf.exe; Driver: C:\Users\RAFA~1\AppData\Local\Temp\kwddakog.sys


---- User code sections - GMER 2.1 ----

.text   C:\Windows\system32\wininit.exe[732] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                                00000000777fef8d 1 byte [62]
.text   C:\Windows\system32\winlogon.exe[844] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                               00000000777fef8d 1 byte [62]
.text   C:\Windows\system32\nvvsvc.exe[388] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                                 00000000777fef8d 1 byte [62]
.text   C:\Windows\System32\svchost.exe[300] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                                00000000777fef8d 1 byte [62]
.text   C:\Windows\system32\svchost.exe[876] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                                00000000777fef8d 1 byte [62]
.text   C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1276] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                    00000000777fef8d 1 byte [62]
.text   C:\Program Files\Intel\WiFi\bin\ZCfgSvc7.exe[1472] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                  00000000777fef8d 1 byte [62]
.text   C:\Windows\system32\WLANExt.exe[1480] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                               00000000777fef8d 1 byte [62]
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRYSVC.EXE[1536] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                        00000000777fef8d 1 byte [62]
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                            00000000777aa400 7 bytes JMP 000000016fff0228
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                          00000000777b3f20 5 bytes JMP 000000016fff0180
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                           00000000777cffb0 5 bytes JMP 000000016fff01b8
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                     00000000777df2e0 5 bytes JMP 000000016fff0110
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                      00000000777fef8d 1 byte [62]
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                   0000000077809a30 7 bytes JMP 000000016fff00d8
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                   00000000778194c0 5 bytes JMP 000000016fff0148
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                            00000000778387e0 7 bytes JMP 000000016fff01f0
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                             000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                        000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                          000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                      000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                       000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                     000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\ole32.dll!CoCreateInstance                                                             000007feff937490 11 bytes JMP 000007fffda20228
.text   C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1580] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                            000007feff94bf00 7 bytes JMP 000007fffda20260
.text   C:\Windows\system32\nvvsvc.exe[1588] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                                00000000777fef8d 1 byte [62]
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe[1648] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                        00000000777fef8d 1 byte [62]
.text   C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1368] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                  000000007736a2fd 1 byte [62]
.text   C:\Program Files (x86)\Bluetooth Suite\adminservice.exe[1844] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                       00000000777fef8d 1 byte [62]
.text   C:\Windows\system32\Dwm.exe[2092] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                                          000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Windows\system32\Dwm.exe[2092] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                                     000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Windows\system32\Dwm.exe[2092] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                                       000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Windows\system32\Dwm.exe[2092] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                                   000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Windows\system32\Dwm.exe[2092] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                                    000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Windows\system32\Dwm.exe[2092] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                                  000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Windows\system32\Dwm.exe[2092] C:\Windows\system32\dxgi.dll!CreateDXGIFactory                                                                                          000007fef56ddc88 5 bytes JMP 000007fff54d00d8
.text   C:\Windows\system32\Dwm.exe[2092] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1                                                                                         000007fef56dde10 5 bytes JMP 000007fff54d0110
.text   C:\Windows\Explorer.EXE[2200] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                                       00000000777fef8d 1 byte [62]
.text   C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[2264] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                        00000000777fef8d 1 byte [62]
.text   C:\Program Files (x86)\Launch Manager\dsiwmis.exe[2332] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                             000000007736a2fd 1 byte [62]
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                                0000000077341f0e 7 bytes JMP 0000000170b13550
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                  0000000077345bad 7 bytes JMP 0000000170b137f0
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                  0000000077351409 7 bytes JMP 0000000170b13650
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                 000000007735ea45 7 bytes JMP 0000000170b13540
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                            000000007736a2fd 1 byte [62]
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                         00000000773e8e24 7 bytes JMP 0000000170b13310
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                         00000000773e8ea9 5 bytes JMP 0000000170b133c0
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                           00000000773e91ff 5 bytes JMP 0000000170b13320
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                              0000000075b81d1b 5 bytes JMP 0000000170b132b0
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                            0000000075b81dc9 5 bytes JMP 0000000170b13270
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                0000000075b82aa4 5 bytes JMP 0000000170b133d0
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                   0000000075b82d0a 5 bytes JMP 0000000170b130b0
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                   0000000075618a29 5 bytes JMP 0000000170b12c60
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                               0000000075624572 5 bytes JMP 0000000170b13030
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                               000000007563e567 5 bytes JMP 0000000170b130a0
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                        0000000075677a5c 5 bytes JMP 0000000170b13020
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                           0000000075a7e96b 5 bytes JMP 0000000170b12cd0
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                             0000000075a7eba5 5 bytes JMP 0000000170b12ce0
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                                  0000000075d05ea5 5 bytes JMP 0000000170b12c20
.text   C:\Program Files (x86)\Launch Manager\LMworker.exe[2364] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                   0000000075d39d0b 5 bytes JMP 0000000170b12bb0
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                              0000000077341f0e 7 bytes JMP 0000000170b13550
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                0000000077345bad 7 bytes JMP 0000000170b137f0
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                0000000077351409 7 bytes JMP 0000000170b13650
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                               000000007735ea45 7 bytes JMP 0000000170b13540
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                          000000007736a2fd 1 byte [62]
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                       00000000773e8e24 7 bytes JMP 0000000170b13310
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                       00000000773e8ea9 5 bytes JMP 0000000170b133c0
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                         00000000773e91ff 5 bytes JMP 0000000170b13320
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                            0000000075b81d1b 5 bytes JMP 0000000170b132b0
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                          0000000075b81dc9 5 bytes JMP 0000000170b13270
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                              0000000075b82aa4 5 bytes JMP 0000000170b133d0
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                 0000000075b82d0a 5 bytes JMP 0000000170b130b0
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                 0000000075618a29 5 bytes JMP 0000000170b12c60
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                             0000000075624572 5 bytes JMP 0000000170b13030
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                             000000007563e567 5 bytes JMP 0000000170b130a0
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                      0000000075677a5c 5 bytes JMP 0000000170b13020
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                         0000000075a7e96b 5 bytes JMP 0000000170b12cd0
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                           0000000075a7eba5 5 bytes JMP 0000000170b12ce0
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                                0000000075d05ea5 5 bytes JMP 0000000170b12c20
.text   C:\Program Files (x86)\Launch Manager\LMutilps32.exe[2372] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                 0000000075d39d0b 5 bytes JMP 0000000170b12bb0
.text   C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[2396] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                        000000007736a2fd 1 byte [62]
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2504] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                            000000007736a2fd 1 byte [62]
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                          0000000076de1465 2 bytes [DE, 76]
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                         0000000076de14bb 2 bytes [DE, 76]
.text   ...                                                                                                                                                                       * 2
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2588] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                              000000007736a2fd 1 byte [62]
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2588] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                            0000000076de1465 2 bytes [DE, 76]
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2588] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                           0000000076de14bb 2 bytes [DE, 76]
.text   ...                                                                                                                                                                       * 2
.text   C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[2612] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                     000000007736a2fd 1 byte [62]
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[2652] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                               00000000777fef8d 1 byte [62]
.text   C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe[2824] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                              000000007736a2fd 1 byte [62]
.text   D:\Programy\LogMeIn Hamachi\hamachi-2.exe[2892] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                     00000000777fef8d 1 byte [62]
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                         0000000077341f0e 7 bytes JMP 0000000170b13550
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                           0000000077345bad 7 bytes JMP 0000000170b137f0
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                           0000000077351409 7 bytes JMP 0000000170b13650
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                          000000007735ea45 7 bytes JMP 0000000170b13540
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                     000000007736a2fd 1 byte [62]
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                  00000000773e8e24 7 bytes JMP 0000000170b13310
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                  00000000773e8ea9 5 bytes JMP 0000000170b133c0
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                    00000000773e91ff 5 bytes JMP 0000000170b13320
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                       0000000075b81d1b 5 bytes JMP 0000000170b132b0
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                     0000000075b81dc9 5 bytes JMP 0000000170b13270
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                         0000000075b82aa4 5 bytes JMP 0000000170b133d0
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                            0000000075b82d0a 5 bytes JMP 0000000170b130b0
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                            0000000075618a29 5 bytes JMP 0000000170b12c60
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                        0000000075624572 5 bytes JMP 0000000170b13030
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                        000000007563e567 5 bytes JMP 0000000170b130a0
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                 0000000075677a5c 5 bytes JMP 0000000170b13020
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                    0000000075a7e96b 5 bytes JMP 0000000170b12cd0
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                      0000000075a7eba5 5 bytes JMP 0000000170b12ce0
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                   0000000076de1465 2 bytes [DE, 76]
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                  0000000076de14bb 2 bytes [DE, 76]
.text   ...                                                                                                                                                                       * 2
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                           0000000075d05ea5 5 bytes JMP 0000000170b12c20
.text   e:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2900] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                            0000000075d39d0b 5 bytes JMP 0000000170b12bb0
.text   C:\Windows\system32\wbem\wmiprvse.exe[3112] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                         00000000777fef8d 1 byte [62]
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                                      0000000077341f0e 7 bytes JMP 0000000170b13550
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                        0000000077345bad 7 bytes JMP 0000000170b137f0
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                        0000000077351409 7 bytes JMP 0000000170b13650
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                       000000007735ea45 7 bytes JMP 0000000170b13540
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                                  000000007736a2fd 1 byte [62]
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                               00000000773e8e24 7 bytes JMP 0000000170b13310
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                               00000000773e8ea9 5 bytes JMP 0000000170b133c0
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                                 00000000773e91ff 5 bytes JMP 0000000170b13320
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                                    0000000075b81d1b 5 bytes JMP 0000000170b132b0
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                                  0000000075b81dc9 5 bytes JMP 0000000170b13270
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                      0000000075b82aa4 5 bytes JMP 0000000170b133d0
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                         0000000075b82d0a 5 bytes JMP 0000000170b130b0
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                         0000000075618a29 5 bytes JMP 0000000170b12c60
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                                     0000000075624572 5 bytes JMP 0000000170b13030
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                                     000000007563e567 5 bytes JMP 0000000170b130a0
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                              0000000075677a5c 5 bytes JMP 0000000170b13020
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                                 0000000075a7e96b 5 bytes JMP 0000000170b12cd0
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                                   0000000075a7eba5 5 bytes JMP 0000000170b12ce0
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\PsApi.dll!GetModuleInformation + 69                                                                0000000076de1465 2 bytes [DE, 76]
.text   D:\Programy\LogMeIn Hamachi\hamachi-2-ui.exe[3676] C:\Windows\syswow64\PsApi.dll!GetModuleInformation + 155                                                               0000000076de14bb 2 bytes [DE, 76]
.text   ...                                                                                                                                                                       * 2
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4004] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                               00000000777fef8d 1 byte [62]
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                     00000000777aa400 7 bytes JMP 000000016fff0228
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                   00000000777b3f20 5 bytes JMP 000000016fff0180
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                    00000000777cffb0 5 bytes JMP 000000016fff01b8
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                              00000000777df2e0 5 bytes JMP 000000016fff0110
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                               00000000777fef8d 1 byte [62]
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                            0000000077809a30 7 bytes JMP 000000016fff00d8
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                            00000000778194c0 5 bytes JMP 000000016fff0148
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                     00000000778387e0 7 bytes JMP 000000016fff01f0
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                      000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                 000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                   000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                               000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\ole32.dll!CoCreateInstance                                                      000007feff937490 11 bytes JMP 000007fffda20228
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                     000007feff94bf00 7 bytes JMP 000007fffda20260
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                              000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\d3d9.dll!Direct3DCreate9Ex                                                      000007fef47d2460 3 bytes JMP 000007fefda202d0
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\d3d9.dll!Direct3DCreate9Ex + 4                                                  000007fef47d2464 1 byte [09]
.text   C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3276] C:\Windows\system32\d3d9.dll!Direct3DCreate9                                                        000007fef48096b0 6 bytes JMP 000007fefda20298
.text   C:\Windows\system32\conhost.exe[3436] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                               00000000777fef8d 1 byte [62]
.text   C:\Windows\System32\rundll32.exe[3600] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                              00000000777fef8d 1 byte [62]
.text   D:\Programy\LogMeIn Hamachi\LMIGuardianSvc.exe[468] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                        000007fefda32db0 5 bytes JMP 000007fffda10180
.text   D:\Programy\LogMeIn Hamachi\LMIGuardianSvc.exe[468] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                   000007fefda337d0 7 bytes JMP 000007fffda100d8
.text   D:\Programy\LogMeIn Hamachi\LMIGuardianSvc.exe[468] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                     000007fefda38ef0 6 bytes JMP 000007fffda10148
.text   D:\Programy\LogMeIn Hamachi\LMIGuardianSvc.exe[468] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                 000007fefda4af60 5 bytes JMP 000007fffda10110
.text   D:\Programy\LogMeIn Hamachi\LMIGuardianSvc.exe[468] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                  000007fefe4289e0 8 bytes JMP 000007fffda101f0
.text   D:\Programy\LogMeIn Hamachi\LMIGuardianSvc.exe[468] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                000007fefe42be40 8 bytes JMP 000007fffda101b8
.text   D:\Programy\LogMeIn Hamachi\LMIGuardianSvc.exe[468] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                        000007feff937490 11 bytes JMP 000007fffda10228
.text   D:\Programy\LogMeIn Hamachi\LMIGuardianSvc.exe[468] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                       000007feff94bf00 7 bytes JMP 000007fffda10260
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                              00000000777aa400 7 bytes JMP 000000016fff0228
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                            00000000777b3f20 5 bytes JMP 000000016fff0180
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                             00000000777cffb0 5 bytes JMP 000000016fff01b8
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                       00000000777df2e0 5 bytes JMP 000000016fff0110
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                        00000000777fef8d 1 byte [62]
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                     0000000077809a30 7 bytes JMP 000000016fff00d8
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                     00000000778194c0 5 bytes JMP 000000016fff0148
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                              00000000778387e0 7 bytes JMP 000000016fff01f0
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                               000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                          000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                            000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                        000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                         000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3728] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                       000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1504] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                              00000000777aa400 7 bytes JMP 000000016fff0228
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1504] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                            00000000777b3f20 5 bytes JMP 000000016fff0180
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1504] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                             00000000777cffb0 5 bytes JMP 000000016fff01b8
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1504] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                       00000000777df2e0 5 bytes JMP 000000016fff0110
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1504] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                        00000000777fef8d 1 byte [62]
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1504] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                     0000000077809a30 7 bytes JMP 000000016fff00d8
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1504] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                     00000000778194c0 5 bytes JMP 000000016fff0148
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1504] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                              00000000778387e0 7 bytes JMP 000000016fff01f0
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1504] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                               000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1504] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                          000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1504] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                            000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1504] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                        000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1504] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                         000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[1504] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                       000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                     00000000777aa400 7 bytes JMP 000000016fff0228
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                   00000000777b3f20 5 bytes JMP 000000016fff0180
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                    00000000777cffb0 5 bytes JMP 000000016fff01b8
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                              00000000777df2e0 5 bytes JMP 000000016fff0110
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               00000000777fef8d 1 byte [62]
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                            0000000077809a30 7 bytes JMP 000000016fff00d8
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                            00000000778194c0 5 bytes JMP 000000016fff0148
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                     00000000778387e0 7 bytes JMP 000000016fff01f0
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                      000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                 000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                   000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                               000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                              000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                      000007feff937490 11 bytes JMP 000007fffda20228
.text   C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[4776] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                     000007feff94bf00 7 bytes JMP 000007fffda20260
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                      00000000777aa400 7 bytes JMP 000000016fff0228
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                    00000000777b3f20 5 bytes JMP 000000016fff0180
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                     00000000777cffb0 5 bytes JMP 000000016fff01b8
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                               00000000777df2e0 5 bytes JMP 000000016fff0110
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                00000000777fef8d 1 byte [62]
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                             0000000077809a30 7 bytes JMP 000000016fff00d8
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                             00000000778194c0 5 bytes JMP 000000016fff0148
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                      00000000778387e0 7 bytes JMP 000000016fff01f0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                       000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                  000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                    000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                       000007feff937490 11 bytes JMP 000007fffda20228
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                      000007feff94bf00 7 bytes JMP 000007fffda20260
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                 000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[4600] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                               000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Windows\System32\igfxpers.exe[2228] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                                     000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Windows\System32\igfxpers.exe[2228] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                                000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Windows\System32\igfxpers.exe[2228] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                                  000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Windows\System32\igfxpers.exe[2228] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                              000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Windows\System32\igfxpers.exe[2228] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                               000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Windows\System32\igfxpers.exe[2228] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                             000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Windows\System32\igfxpers.exe[2228] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                     000007feff937490 11 bytes JMP 000007fffda20228
.text   C:\Windows\System32\igfxpers.exe[2228] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                                    000007feff94bf00 7 bytes JMP 000007fffda20260
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                                00000000777aa400 7 bytes JMP 000000016fff0228
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                              00000000777b3f20 5 bytes JMP 000000016fff0180
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                               00000000777cffb0 5 bytes JMP 000000016fff01b8
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                                         00000000777df2e0 5 bytes JMP 000000016fff0110
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                          00000000777fef8d 1 byte [62]
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                                       0000000077809a30 7 bytes JMP 000000016fff00d8
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                                       00000000778194c0 5 bytes JMP 000000016fff0148
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                                00000000778387e0 7 bytes JMP 000000016fff01f0
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                                 000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                            000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                              000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                          000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                           000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                         000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                 000007feff937490 11 bytes JMP 000007fffda20228
.text   C:\Program Files\Elantech\ETDCtrl.exe[204] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                                000007feff94bf00 7 bytes JMP 000007fffda20260
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1988] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                        000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1988] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                   000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1988] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                     000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1988] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                 000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1988] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                  000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1988] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1988] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                        000007feff937490 11 bytes JMP 000007fffda20228
.text   C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[1988] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                       000007feff94bf00 7 bytes JMP 000007fffda20260
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\KERNEL32.dll!RegSetValueExW                                                00000000777aa400 7 bytes JMP 000000016fff0228
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW                                              00000000777b3f20 5 bytes JMP 000000016fff0180
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW                                               00000000777cffb0 5 bytes JMP 000000016fff01b8
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW                                         00000000777df2e0 5 bytes JMP 000000016fff0110
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                          00000000777fef8d 1 byte [62]
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx                                       0000000077809a30 7 bytes JMP 000000016fff00d8
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation                                       00000000778194c0 5 bytes JMP 000000016fff0148
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\KERNEL32.dll!RegSetValueExA                                                00000000778387e0 7 bytes JMP 000000016fff01f0
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                 000007fefda32db0 5 bytes JMP 000007fffd810180
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                            000007fefda337d0 7 bytes JMP 000007fffd8100d8
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                              000007fefda38ef0 6 bytes JMP 000007fffd810148
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                          000007fefda4af60 5 bytes JMP 000007fffd810110
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                           000007fefe4289e0 8 bytes JMP 000007fffd8101f0
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                         000007fefe42be40 8 bytes JMP 000007fffd8101b8
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\ole32.dll!CoCreateInstance                                                 000007feff937490 11 bytes JMP 000007fffd810228
.text   C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[4684] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                000007feff94bf00 7 bytes JMP 000007fffd810260
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                     00000000777aa400 7 bytes JMP 000000016fff0228
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                   00000000777b3f20 5 bytes JMP 000000016fff0180
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                    00000000777cffb0 5 bytes JMP 000000016fff01b8
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                              00000000777df2e0 5 bytes JMP 000000016fff0110
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                               00000000777fef8d 1 byte [62]
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                            0000000077809a30 7 bytes JMP 000000016fff00d8
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                            00000000778194c0 5 bytes JMP 000000016fff0148
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                     00000000778387e0 7 bytes JMP 000000016fff01f0
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                      000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                 000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                   000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                               000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                              000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\ole32.dll!CoCreateInstance                                                      000007feff937490 11 bytes JMP 000007fffda20228
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2480] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                     000007feff94bf00 7 bytes JMP 000007fffda20260
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                 00000000777aa400 7 bytes JMP 000000016fff0228
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                               00000000777b3f20 5 bytes JMP 000000016fff0180
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                00000000777cffb0 5 bytes JMP 000000016fff01b8
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                          00000000777df2e0 5 bytes JMP 000000016fff0110
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                           00000000777fef8d 1 byte [62]
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                        0000000077809a30 7 bytes JMP 000000016fff00d8
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                        00000000778194c0 5 bytes JMP 000000016fff0148
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                 00000000778387e0 7 bytes JMP 000000016fff01f0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                  000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                             000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                               000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                           000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                            000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                          000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                  000007feff937490 11 bytes JMP 000007fffda20228
.text   C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe[1604] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                 000007feff94bf00 7 bytes JMP 000007fffda20260
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                     00000000777aa400 7 bytes JMP 000000016fff0228
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                   00000000777b3f20 5 bytes JMP 000000016fff0180
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                    00000000777cffb0 5 bytes JMP 000000016fff01b8
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                              00000000777df2e0 5 bytes JMP 000000016fff0110
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                               00000000777fef8d 1 byte [62]
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                            0000000077809a30 7 bytes JMP 000000016fff00d8
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                            00000000778194c0 5 bytes JMP 000000016fff0148
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                     00000000778387e0 7 bytes JMP 000000016fff01f0
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                      000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                 000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                   000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                               000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                              000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\ole32.dll!CoCreateInstance                                                      000007feff937490 11 bytes JMP 000007fffda20228
.text   C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe[2940] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                     000007feff94bf00 7 bytes JMP 000007fffda20260
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                               0000000077341f0e 7 bytes JMP 0000000170b13550
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                 0000000077345bad 7 bytes JMP 0000000170b137f0
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                 0000000077351409 7 bytes JMP 0000000170b13650
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                000000007735ea45 7 bytes JMP 0000000170b13540
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                           000000007736a2fd 1 byte [62]
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                        00000000773e8e24 7 bytes JMP 0000000170b13310
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                        00000000773e8ea9 5 bytes JMP 0000000170b133c0
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                          00000000773e91ff 5 bytes JMP 0000000170b13320
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                             0000000075b81d1b 5 bytes JMP 0000000170b132b0
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                           0000000075b81dc9 5 bytes JMP 0000000170b13270
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                               0000000075b82aa4 5 bytes JMP 0000000170b133d0
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                  0000000075b82d0a 5 bytes JMP 0000000170b130b0
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                  0000000075618a29 5 bytes JMP 0000000170b12c60
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                              0000000075624572 5 bytes JMP 0000000170b13030
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                              000000007563e567 5 bytes JMP 0000000170b130a0
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                       0000000075677a5c 5 bytes JMP 0000000170b13020
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                          0000000075a7e96b 5 bytes JMP 0000000170b12cd0
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                            0000000075a7eba5 5 bytes JMP 0000000170b12ce0
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                 0000000075d05ea5 5 bytes JMP 0000000170b12c20
.text   C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[1240] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                  0000000075d39d0b 5 bytes JMP 0000000170b12bb0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                            0000000077341f0e 7 bytes JMP 0000000170b13550
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                              0000000077345bad 7 bytes JMP 0000000170b137f0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                              0000000077351409 7 bytes JMP 0000000170b13650
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                             000000007735ea45 7 bytes JMP 0000000170b13540
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                        000000007736a2fd 1 byte [62]
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                     00000000773e8e24 7 bytes JMP 0000000170b13310
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                     00000000773e8ea9 5 bytes JMP 0000000170b133c0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                       00000000773e91ff 5 bytes JMP 0000000170b13320
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                          0000000075b81d1b 5 bytes JMP 0000000170b132b0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                        0000000075b81dc9 5 bytes JMP 0000000170b13270
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                            0000000075b82aa4 5 bytes JMP 0000000170b133d0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                               0000000075b82d0a 5 bytes JMP 0000000170b130b0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                               0000000075618a29 5 bytes JMP 0000000170b12c60
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                           0000000075624572 5 bytes JMP 0000000170b13030
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                           000000007563e567 5 bytes JMP 0000000170b130a0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                    0000000075677a5c 5 bytes JMP 0000000170b13020
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                       0000000075a7e96b 5 bytes JMP 0000000170b12cd0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                         0000000075a7eba5 5 bytes JMP 0000000170b12ce0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                      0000000076de1465 2 bytes [DE, 76]
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                     0000000076de14bb 2 bytes [DE, 76]
.text   ...                                                                                                                                                                       * 2
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                              0000000075d05ea5 5 bytes JMP 0000000170b12c20
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[1032] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                               0000000075d39d0b 5 bytes JMP 0000000170b12bb0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                             0000000077341f0e 7 bytes JMP 0000000170b13550
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                               0000000077345bad 7 bytes JMP 0000000170b137f0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                               0000000077351409 7 bytes JMP 0000000170b13650
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                              000000007735ea45 7 bytes JMP 0000000170b13540
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                         000000007736a2fd 1 byte [62]
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                      00000000773e8e24 7 bytes JMP 0000000170b13310
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                      00000000773e8ea9 5 bytes JMP 0000000170b133c0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                        00000000773e91ff 5 bytes JMP 0000000170b13320
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                           0000000075b81d1b 5 bytes JMP 0000000170b132b0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                         0000000075b81dc9 5 bytes JMP 0000000170b13270
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                             0000000075b82aa4 5 bytes JMP 0000000170b133d0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                0000000075b82d0a 5 bytes JMP 0000000170b130b0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                0000000075618a29 5 bytes JMP 0000000170b12c60
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                            0000000075624572 5 bytes JMP 0000000170b13030
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                            000000007563e567 5 bytes JMP 0000000170b130a0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                     0000000075677a5c 5 bytes JMP 0000000170b13020
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                        0000000075a7e96b 5 bytes JMP 0000000170b12cd0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                          0000000075a7eba5 5 bytes JMP 0000000170b12ce0
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                       0000000076de1465 2 bytes [DE, 76]
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                      0000000076de14bb 2 bytes [DE, 76]
.text   ...                                                                                                                                                                       * 2
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                               0000000075d05ea5 5 bytes JMP 0000000170b12c20
.text   C:\Users\Rafa許AppData\Local\Akamai\netsession_win.exe[288] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                0000000075d39d0b 5 bytes JMP 0000000170b12bb0
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\KERNEL32.dll!RegSetValueExW                                                                                            00000000777aa400 7 bytes JMP 000000016fff0228
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW                                                                                          00000000777b3f20 5 bytes JMP 000000016fff0180
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW                                                                                           00000000777cffb0 5 bytes JMP 000000016fff01b8
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW                                                                                     00000000777df2e0 5 bytes JMP 000000016fff0110
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                                                                      00000000777fef8d 1 byte [62]
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx                                                                                   0000000077809a30 7 bytes JMP 000000016fff00d8
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation                                                                                   00000000778194c0 5 bytes JMP 000000016fff0148
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\KERNEL32.dll!RegSetValueExA                                                                                            00000000778387e0 7 bytes JMP 000000016fff01f0
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                                             000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                                        000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                                          000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                                      000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                                       000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                                     000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                             000007feff937490 11 bytes JMP 000007fffda20228
.text   C:\Dolby PCEE4\pcee4.exe[2600] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                                            000007feff94bf00 7 bytes JMP 000007fffda20260
.text   C:\Windows\system32\wbem\unsecapp.exe[1332] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                                000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Windows\system32\wbem\unsecapp.exe[1332] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                           000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Windows\system32\wbem\unsecapp.exe[1332] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                             000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Windows\system32\wbem\unsecapp.exe[1332] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                         000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Windows\system32\wbem\unsecapp.exe[1332] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                000007feff937490 11 bytes JMP 000007fffda20228
.text   C:\Windows\system32\wbem\unsecapp.exe[1332] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                               000007feff94bf00 7 bytes JMP 000007fffda20260
.text   C:\Windows\system32\wbem\unsecapp.exe[1332] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                          000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Windows\system32\wbem\unsecapp.exe[1332] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                        000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW          0000000077341f0e 7 bytes JMP 0000000170b13550
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\kernel32.dll!RegSetValueExW            0000000077345bad 7 bytes JMP 0000000170b137f0
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\kernel32.dll!RegSetValueExA            0000000077351409 7 bytes JMP 0000000170b13650
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW           000000007735ea45 7 bytes JMP 0000000170b13540
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112      000000007736a2fd 1 byte [62]
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx   00000000773e8e24 7 bytes JMP 0000000170b13310
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation   00000000773e8ea9 5 bytes JMP 0000000170b133c0
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW     00000000773e91ff 5 bytes JMP 0000000170b13320
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW        0000000075b81d1b 5 bytes JMP 0000000170b132b0
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW      0000000075b81dc9 5 bytes JMP 0000000170b13270
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW          0000000075b82aa4 5 bytes JMP 0000000170b133d0
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary             0000000075b82d0a 5 bytes JMP 0000000170b130b0
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList     0000000075a7e96b 5 bytes JMP 0000000170b12cd0
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo       0000000075a7eba5 5 bytes JMP 0000000170b12ce0
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\USER32.dll!CreateWindowExW             0000000075618a29 5 bytes JMP 0000000170b12c60
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA         0000000075624572 5 bytes JMP 0000000170b13030
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW         000000007563e567 5 bytes JMP 0000000170b130a0
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo  0000000075677a5c 5 bytes JMP 0000000170b13020
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket            0000000075d05ea5 5 bytes JMP 0000000170b12c20
.text   C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4672] C:\Windows\syswow64\ole32.dll!CoCreateInstance             0000000075d39d0b 5 bytes JMP 0000000170b12bb0
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW                                      0000000077341f0e 7 bytes JMP 0000000170b13550
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW                                        0000000077345bad 7 bytes JMP 0000000170b137f0
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA                                        0000000077351409 7 bytes JMP 0000000170b13650
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW                                       000000007735ea45 7 bytes JMP 0000000170b13540
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                                  000000007736a2fd 1 byte [62]
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx                               00000000773e8e24 7 bytes JMP 0000000170b13310
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation                               00000000773e8ea9 5 bytes JMP 0000000170b133c0
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW                                 00000000773e91ff 5 bytes JMP 0000000170b13320
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                    0000000075b81d1b 5 bytes JMP 0000000170b132b0
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                  0000000075b81dc9 5 bytes JMP 0000000170b13270
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                      0000000075b82aa4 5 bytes JMP 0000000170b133d0
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                         0000000075b82d0a 5 bytes JMP 0000000170b130b0
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                 0000000075a7e96b 5 bytes JMP 0000000170b12cd0
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                   0000000075a7eba5 5 bytes JMP 0000000170b12ce0
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                         0000000075618a29 5 bytes JMP 0000000170b12c60
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                     0000000075624572 5 bytes JMP 0000000170b13030
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                     000000007563e567 5 bytes JMP 0000000170b130a0
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                              0000000075677a5c 5 bytes JMP 0000000170b13020
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                        0000000075d05ea5 5 bytes JMP 0000000170b12c20
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[976] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                         0000000075d39d0b 5 bytes JMP 0000000170b12bb0
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                                0000000077341f0e 7 bytes JMP 0000000170b13550
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                  0000000077345bad 7 bytes JMP 0000000170b137f0
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                  0000000077351409 7 bytes JMP 0000000170b13650
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                 000000007735ea45 7 bytes JMP 0000000170b13540
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                            000000007736a2fd 1 byte [62]
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                         00000000773e8e24 7 bytes JMP 0000000170b13310
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                         00000000773e8ea9 5 bytes JMP 0000000170b133c0
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                           00000000773e91ff 5 bytes JMP 0000000170b13320
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                              0000000075b81d1b 5 bytes JMP 0000000170b132b0
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                            0000000075b81dc9 5 bytes JMP 0000000170b13270
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                0000000075b82aa4 5 bytes JMP 0000000170b133d0
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                   0000000075b82d0a 5 bytes JMP 0000000170b130b0
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                           0000000075a7e96b 5 bytes JMP 0000000170b12cd0
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                             0000000075a7eba5 5 bytes JMP 0000000170b12ce0
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                   0000000075618a29 5 bytes JMP 0000000170b12c60
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                               0000000075624572 5 bytes JMP 0000000170b13030
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                               000000007563e567 5 bytes JMP 0000000170b130a0
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                        0000000075677a5c 5 bytes JMP 0000000170b13020
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                                  0000000075d05ea5 5 bytes JMP 0000000170b12c20
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                   0000000075d39d0b 5 bytes JMP 0000000170b12bb0
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                          0000000076de1465 2 bytes [DE, 76]
.text   C:\Program Files (x86)\Launch Manager\LManager.exe[4676] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                         0000000076de14bb 2 bytes [DE, 76]
.text   ...                                                                                                                                                                       * 2
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                           0000000077341f0e 7 bytes JMP 0000000170b13550
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                             0000000077345bad 7 bytes JMP 0000000170b137f0
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                             0000000077351409 7 bytes JMP 0000000170b13650
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                            000000007735ea45 7 bytes JMP 0000000170b13540
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                       000000007736a2fd 1 byte [62]
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                    00000000773e8e24 7 bytes JMP 0000000170b13310
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                    00000000773e8ea9 5 bytes JMP 0000000170b133c0
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                      00000000773e91ff 5 bytes JMP 0000000170b13320
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                         0000000075b81d1b 5 bytes JMP 0000000170b132b0
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                       0000000075b81dc9 5 bytes JMP 0000000170b13270
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                           0000000075b82aa4 5 bytes JMP 0000000170b133d0
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                              0000000075b82d0a 5 bytes JMP 0000000170b130b0
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                      0000000075a7e96b 5 bytes JMP 0000000170b12cd0
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                        0000000075a7eba5 5 bytes JMP 0000000170b12ce0
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                              0000000075618a29 5 bytes JMP 0000000170b12c60
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                          0000000075624572 5 bytes JMP 0000000170b13030
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                          000000007563e567 5 bytes JMP 0000000170b130a0
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                   0000000075677a5c 5 bytes JMP 0000000170b13020
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                             0000000075d05ea5 5 bytes JMP 0000000170b12c20
.text   C:\Program Files (x86)\Hostless Modem\CheckNDISPort.exe[3064] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                              0000000075d39d0b 5 bytes JMP 0000000170b12bb0
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                       0000000077341f0e 7 bytes JMP 0000000170b13550
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                         0000000077345bad 7 bytes JMP 0000000170b137f0
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                         0000000077351409 7 bytes JMP 0000000170b13650
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                        000000007735ea45 7 bytes JMP 0000000170b13540
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                   000000007736a2fd 1 byte [62]
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                00000000773e8e24 7 bytes JMP 0000000170b13310
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                00000000773e8ea9 5 bytes JMP 0000000170b133c0
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                  00000000773e91ff 5 bytes JMP 0000000170b13320
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                     0000000075b81d1b 5 bytes JMP 0000000170b132b0
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                   0000000075b81dc9 5 bytes JMP 0000000170b13270
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                       0000000075b82aa4 5 bytes JMP 0000000170b133d0
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                          0000000075b82d0a 5 bytes JMP 0000000170b130b0
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                          0000000075618a29 5 bytes JMP 0000000170b12c60
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                      0000000075624572 5 bytes JMP 0000000170b13030
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                      000000007563e567 5 bytes JMP 0000000170b130a0
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                               0000000075677a5c 5 bytes JMP 0000000170b13020
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                  0000000075a7e96b 5 bytes JMP 0000000170b12cd0
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                    0000000075a7eba5 5 bytes JMP 0000000170b12ce0
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                         0000000075d05ea5 5 bytes JMP 0000000170b12c20
.text   C:\Program Files (x86)\Hostless Modem\CancelAutoPlay_60.exe[4092] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                          0000000075d39d0b 5 bytes JMP 0000000170b12bb0
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                  0000000077341f0e 7 bytes JMP 0000000170b13550
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                    0000000077345bad 7 bytes JMP 0000000170b137f0
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                    0000000077351409 7 bytes JMP 0000000170b13650
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                   000000007735ea45 7 bytes JMP 0000000170b13540
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                              000000007736a2fd 1 byte [62]
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                           00000000773e8e24 7 bytes JMP 0000000170b13310
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                           00000000773e8ea9 5 bytes JMP 0000000170b133c0
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                             00000000773e91ff 5 bytes JMP 0000000170b13320
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                0000000075b81d1b 5 bytes JMP 0000000170b132b0
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                              0000000075b81dc9 5 bytes JMP 0000000170b13270
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                  0000000075b82aa4 5 bytes JMP 0000000170b133d0
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                     0000000075b82d0a 5 bytes JMP 0000000170b130b0
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                             0000000075a7e96b 5 bytes JMP 0000000170b12cd0
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                               0000000075a7eba5 5 bytes JMP 0000000170b12ce0
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                     0000000075618a29 5 bytes JMP 0000000170b12c60
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                 0000000075624572 5 bytes JMP 0000000170b13030
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                 000000007563e567 5 bytes JMP 0000000170b130a0
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                          0000000075677a5c 5 bytes JMP 0000000170b13020
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                    0000000075d05ea5 5 bytes JMP 0000000170b12c20
.text   C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4628] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                     0000000075d39d0b 5 bytes JMP 0000000170b12bb0
.text   C:\Program Files\AVAST Software\Avast\AvastUI.exe[3544] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                             000000007736a2fd 1 byte [62]
.text   C:\Program Files\Elantech\ETDCtrlHelper.exe[2932] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                         00000000777aa400 7 bytes JMP 000000016fff0228
.text   C:\Program Files\Elantech\ETDCtrlHelper.exe[2932] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                       00000000777b3f20 5 bytes JMP 000000016fff0180
.text   C:\Program Files\Elantech\ETDCtrlHelper.exe[2932] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                        00000000777cffb0 5 bytes JMP 000000016fff01b8
.text   C:\Program Files\Elantech\ETDCtrlHelper.exe[2932] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                                  00000000777df2e0 5 bytes JMP 000000016fff0110
.text   C:\Program Files\Elantech\ETDCtrlHelper.exe[2932] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                   00000000777fef8d 1 byte [62]
.text   C:\Program Files\Elantech\ETDCtrlHelper.exe[2932] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                                0000000077809a30 7 bytes JMP 000000016fff00d8
.text   C:\Program Files\Elantech\ETDCtrlHelper.exe[2932] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                                00000000778194c0 5 bytes JMP 000000016fff0148
.text   C:\Program Files\Elantech\ETDCtrlHelper.exe[2932] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                         00000000778387e0 7 bytes JMP 000000016fff01f0
.text   C:\Program Files\Elantech\ETDCtrlHelper.exe[2932] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                          000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Program Files\Elantech\ETDCtrlHelper.exe[2932] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                     000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Program Files\Elantech\ETDCtrlHelper.exe[2932] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                       000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Program Files\Elantech\ETDCtrlHelper.exe[2932] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                   000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Program Files\Elantech\ETDCtrlHelper.exe[2932] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                    000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Program Files\Elantech\ETDCtrlHelper.exe[2932] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                  000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[4040] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                   000007fefda32db0 5 bytes JMP 000007fffda20180
.text   C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[4040] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                              000007fefda337d0 7 bytes JMP 000007fffda200d8
.text   C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[4040] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                000007fefda38ef0 6 bytes JMP 000007fffda20148
.text   C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[4040] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                            000007fefda4af60 5 bytes JMP 000007fffda20110
.text   C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[4040] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                             000007fefe4289e0 8 bytes JMP 000007fffda201f0
.text   C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[4040] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                           000007fefe42be40 8 bytes JMP 000007fffda201b8
.text   C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[4040] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                   000007feff937490 11 bytes JMP 000007fffda20228
.text   C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[4040] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                  000007feff94bf00 7 bytes JMP 000007fffda20260
.text   C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[3944] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                           000000007736a2fd 1 byte [62]
.text   C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5944] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                000000007736a2fd 1 byte [62]
.text   C:\Windows\System32\svchost.exe[6116] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                               00000000777fef8d 1 byte [62]
.text   C:\Program Files\Windows Media Player\wmpnetwk.exe[5464] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                            00000000777fef8d 1 byte [62]
.text   C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5832] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                000000007736a2fd 1 byte [62]
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                                               0000000077341f0e 7 bytes JMP 0000000170b13550
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                                 0000000077345bad 7 bytes JMP 0000000170b137f0
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                                 0000000077351409 7 bytes JMP 0000000170b13650
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                                000000007735ea45 7 bytes JMP 0000000170b13540
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                                           000000007736a2fd 1 byte [62]
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                                        00000000773e8e24 7 bytes JMP 0000000170b13310
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                                        00000000773e8ea9 5 bytes JMP 0000000170b133c0
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                                          00000000773e91ff 5 bytes JMP 0000000170b13320
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                                             0000000075b81d1b 5 bytes JMP 0000000170b132b0
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                                           0000000075b81dc9 5 bytes JMP 0000000170b13270
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                               0000000075b82aa4 5 bytes JMP 0000000170b133d0
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                                  0000000075b82d0a 5 bytes JMP 0000000170b130b0
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                                          0000000075a7e96b 5 bytes JMP 0000000170b12cd0
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                                            0000000075a7eba5 5 bytes JMP 0000000170b12ce0
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                                  0000000075618a29 5 bytes JMP 0000000170b12c60
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                                              0000000075624572 5 bytes JMP 0000000170b13030
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                                              000000007563e567 5 bytes JMP 0000000170b130a0
.text   C:\Users\Rafa許Desktop\q52uzqrf.exe[5176] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                                       0000000075677a5c 5 bytes JMP 0000000170b13020

---- Threads - GMER 2.1 ----

Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4852:4124]                                                                                                    0000000077af3e85
Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4852:2448]                                                                                                    00000000770b7587
Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4852:1168]                                                                                                    0000000073cb7712
Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4852:3012]                                                                                                    0000000077af2e65
Thread  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [4852:6112]                                                                                                    0000000077af3e85

---- Registry - GMER 2.1 ----

Reg     HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\083e8e3d34a2                                                                                               
Reg     HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\083e8e3d34a2 (not active ControlSet)                                                                           

---- EOF - GMER 2.1 ----
