GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2015-06-02 15:12:02
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950032 rev.0001 465,76GB
Running: ijgd35kp.exe; Driver: C:\Users\Kamil\AppData\Local\Temp\pwldykoc.sys


---- User code sections - GMER 2.1 ----

.text  C:\Windows\system32\wininit.exe[712] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                                000000007716ef8d 1 byte [62]
.text  C:\Windows\system32\services.exe[768] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                               000000007716ef8d 1 byte [62]
.text  C:\Windows\system32\winlogon.exe[856] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                               000000007716ef8d 1 byte [62]
.text  C:\Windows\System32\svchost.exe[668] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                                000000007716ef8d 1 byte [62]
.text  C:\Windows\system32\svchost.exe[924] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                                000000007716ef8d 1 byte [62]
.text  C:\Program Files (x86)\Launch Manager\dsiwmis.exe[1752] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                             000000007643a2fd 1 byte [62]
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                              0000000076411f0e 7 bytes JMP 0000000171f93d10
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                0000000076415bad 7 bytes JMP 0000000171f946b0
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                0000000076421409 7 bytes JMP 0000000171f94050
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                               000000007642ea45 7 bytes JMP 0000000171f93d00
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                          000000007643a2fd 1 byte [62]
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                       00000000764b8e24 7 bytes JMP 0000000171f937c0
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                       00000000764b8ea9 5 bytes JMP 0000000171f93870
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                         00000000764b91ff 5 bytes JMP 0000000171f937d0
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                            0000000076211d29 5 bytes JMP 0000000171f93780
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                          0000000076211dd7 5 bytes JMP 0000000171f93740
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                              0000000076212ab1 5 bytes JMP 0000000171f93880
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                 0000000076212d17 5 bytes JMP 0000000171f93560
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                 00000000769e8a29 5 bytes JMP 0000000171f92c50
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                             00000000769f4572 5 bytes JMP 0000000171f934e0
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                             0000000076a0e567 5 bytes JMP 0000000171f93550
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                                                        0000000076a307d7 5 bytes JMP 0000000171f92a60
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                      0000000076a47a5c 5 bytes JMP 0000000171f934d0
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                         000000007601e96b 5 bytes JMP 0000000171f92d70
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                           000000007601eba5 5 bytes JMP 0000000171f92d80
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                                0000000076885ea5 5 bytes JMP 0000000171f92c10
.text  C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1800] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                 00000000768b9d0b 5 bytes JMP 0000000171f92ba0
.text  C:\Program Files (x86)\Acer\Registration\GREGsvc.exe[1852] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                          000000007643a2fd 1 byte [62]
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[1956] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                        000000007643a2fd 1 byte [62]
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[1956] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                      00000000763f1465 2 bytes [3F, 76]
.text  C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe[1956] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                     00000000763f14bb 2 bytes [3F, 76]
.text  ...                                                                                                                                                                       * 2
.text  C:\Program Files\Acer\Acer Updater\UpdaterService.exe[1988] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                         000000007643a2fd 1 byte [62]
.text  C:\ProgramData\MobileBrServ\mbbservice.exe[2020] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                                    000000007643a2fd 1 byte [62]
.text  C:\Windows\system32\msiexec.exe[2044] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                               000000007716ef8d 1 byte [62]
.text  C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe[1144] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                     000000007643a2fd 1 byte [62]
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1248] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                               000000007716ef8d 1 byte [62]
.text  C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe[1660] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                               000000007643a2fd 1 byte [62]
.text  C:\Windows\system32\Dwm.exe[3064] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                                          000007fefd382db0 5 bytes JMP 000007fffd370180
.text  C:\Windows\system32\Dwm.exe[3064] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                                     000007fefd3837d0 7 bytes JMP 000007fffd3700d8
.text  C:\Windows\system32\Dwm.exe[3064] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                                       000007fefd388ef0 6 bytes JMP 000007fffd370148
.text  C:\Windows\system32\Dwm.exe[3064] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                                   000007fefd39af60 5 bytes JMP 000007fffd370110
.text  C:\Windows\system32\Dwm.exe[3064] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                                    000007fefd8589f0 8 bytes JMP 000007fffd3701f0
.text  C:\Windows\system32\Dwm.exe[3064] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                                  000007fefd85be50 8 bytes JMP 000007fffd3701b8
.text  C:\Windows\system32\Dwm.exe[3064] C:\Windows\system32\dxgi.dll!CreateDXGIFactory                                                                                          000007fef6b9dc88 5 bytes JMP 000007fff6b700d8
.text  C:\Windows\system32\Dwm.exe[3064] C:\Windows\system32\dxgi.dll!CreateDXGIFactory1                                                                                         000007fef6b9de10 5 bytes JMP 000007fff6b70110
.text  C:\Windows\Explorer.EXE[2080] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                                       000000007716ef8d 1 byte [62]
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                     000000007711a400 7 bytes JMP 000000016fff0228
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                   0000000077123f20 5 bytes JMP 000000016fff0180
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                    000000007713ffb0 5 bytes JMP 000000016fff01b8
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                              000000007714f2e0 5 bytes JMP 000000016fff0110
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                               000000007716ef8d 1 byte [62]
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                            0000000077179a30 7 bytes JMP 000000016fff00d8
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                            00000000771894c0 5 bytes JMP 000000016fff0148
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                     00000000771a87e0 7 bytes JMP 000000016fff01f0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                      000007fefd382db0 5 bytes JMP 000007fffd370180
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                 000007fefd3837d0 7 bytes JMP 000007fffd3700d8
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                   000007fefd388ef0 6 bytes JMP 000007fffd370148
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                               000007fefd39af60 5 bytes JMP 000007fffd370110
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\ole32.dll!CoCreateInstance                                                      000007fefdfb7490 11 bytes JMP 000007fffd370228
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                     000007fefdfcbf00 7 bytes JMP 000007fffd370260
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                000007fefd8589f0 8 bytes JMP 000007fffd3701f0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                              000007fefd85be50 8 bytes JMP 000007fffd3701b8
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\d3d9.dll!Direct3DCreate9Ex                                                      000007fef8af2460 5 bytes JMP 000007fefd3702d0
.text  C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[3112] C:\Windows\system32\d3d9.dll!Direct3DCreate9                                                        000007fef8b296b0 6 bytes JMP 000007fefd370298
.text  C:\Windows\system32\conhost.exe[3120] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                               000000007716ef8d 1 byte [62]
.text  C:\Windows\System32\igfxpers.exe[3380] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                                     000007fefd382db0 5 bytes JMP 000007fffd370180
.text  C:\Windows\System32\igfxpers.exe[3380] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                                000007fefd3837d0 7 bytes JMP 000007fffd3700d8
.text  C:\Windows\System32\igfxpers.exe[3380] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                                  000007fefd388ef0 6 bytes JMP 000007fffd370148
.text  C:\Windows\System32\igfxpers.exe[3380] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                              000007fefd39af60 5 bytes JMP 000007fffd370110
.text  C:\Windows\System32\igfxpers.exe[3380] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                               000007fefd8589f0 8 bytes JMP 000007fffd3701f0
.text  C:\Windows\System32\igfxpers.exe[3380] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                             000007fefd85be50 8 bytes JMP 000007fffd3701b8
.text  C:\Windows\System32\igfxpers.exe[3380] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                     000007fefdfb7490 11 bytes JMP 000007fffd370228
.text  C:\Windows\System32\igfxpers.exe[3380] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                                    000007fefdfcbf00 7 bytes JMP 000007fffd370260
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                     000000007711a400 7 bytes JMP 000000016fff0228
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                   0000000077123f20 5 bytes JMP 000000016fff0180
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                    000000007713ffb0 5 bytes JMP 000000016fff01b8
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                              000000007714f2e0 5 bytes JMP 000000016fff0110
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007716ef8d 1 byte [62]
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                            0000000077179a30 7 bytes JMP 000000016fff00d8
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                            00000000771894c0 5 bytes JMP 000000016fff0148
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                     00000000771a87e0 7 bytes JMP 000000016fff01f0
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                      000007fefd382db0 5 bytes JMP 000007fffd370180
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                 000007fefd3837d0 7 bytes JMP 000007fffd3700d8
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                   000007fefd388ef0 6 bytes JMP 000007fffd370148
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                               000007fefd39af60 5 bytes JMP 000007fffd370110
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                000007fefd8589f0 8 bytes JMP 000007fffd3701f0
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                              000007fefd85be50 8 bytes JMP 000007fffd3701b8
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                      000007fefdfb7490 11 bytes JMP 000007fffd370228
.text  C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3620] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                     000007fefdfcbf00 7 bytes JMP 000007fffd370260
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                      000000007711a400 7 bytes JMP 000000016fff0228
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                    0000000077123f20 5 bytes JMP 000000016fff0180
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                     000000007713ffb0 5 bytes JMP 000000016fff01b8
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                               000000007714f2e0 5 bytes JMP 000000016fff0110
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                000000007716ef8d 1 byte [62]
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                             0000000077179a30 7 bytes JMP 000000016fff00d8
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                             00000000771894c0 5 bytes JMP 000000016fff0148
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                      00000000771a87e0 7 bytes JMP 000000016fff01f0
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                       000007fefd382db0 5 bytes JMP 000007fffd370180
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                  000007fefd3837d0 7 bytes JMP 000007fffd3700d8
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                    000007fefd388ef0 6 bytes JMP 000007fffd370148
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                000007fefd39af60 5 bytes JMP 000007fffd370110
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                       000007fefdfb7490 11 bytes JMP 000007fffd370228
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                      000007fefdfcbf00 7 bytes JMP 000007fffd370260
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                 000007fefd8589f0 8 bytes JMP 000007fffd3701f0
.text  C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe[3700] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                               000007fefd85be50 8 bytes JMP 000007fffd3701b8
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                               000000007711a400 7 bytes JMP 000000016fff0228
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                             0000000077123f20 5 bytes JMP 000000016fff0180
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                              000000007713ffb0 5 bytes JMP 000000016fff01b8
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                                        000000007714f2e0 5 bytes JMP 000000016fff0110
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                         000000007716ef8d 1 byte [62]
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                                      0000000077179a30 7 bytes JMP 000000016fff00d8
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                                      00000000771894c0 5 bytes JMP 000000016fff0148
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                               00000000771a87e0 7 bytes JMP 000000016fff01f0
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                                000007fefd382db0 5 bytes JMP 000007fffd370180
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                           000007fefd3837d0 7 bytes JMP 000007fffd3700d8
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                             000007fefd388ef0 6 bytes JMP 000007fffd370148
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                         000007fefd39af60 5 bytes JMP 000007fffd370110
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                          000007fefd8589f0 8 bytes JMP 000007fffd3701f0
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                        000007fefd85be50 8 bytes JMP 000007fffd3701b8
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                000007fefdfb7490 11 bytes JMP 000007fffd370228
.text  C:\Program Files\Elantech\ETDCtrl.exe[3756] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                               000007fefdfcbf00 7 bytes JMP 000007fffd370260
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\KERNEL32.dll!RegSetValueExW                                                000000007711a400 7 bytes JMP 000000016fff0228
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW                                              0000000077123f20 5 bytes JMP 000000016fff0180
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW                                               000000007713ffb0 5 bytes JMP 000000016fff01b8
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW                                         000000007714f2e0 5 bytes JMP 000000016fff0110
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                          000000007716ef8d 1 byte [62]
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx                                       0000000077179a30 7 bytes JMP 000000016fff00d8
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation                                       00000000771894c0 5 bytes JMP 000000016fff0148
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\KERNEL32.dll!RegSetValueExA                                                00000000771a87e0 7 bytes JMP 000000016fff01f0
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                 000007fefd382db0 5 bytes JMP 000007fffd300180
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                            000007fefd3837d0 7 bytes JMP 000007fffd3000d8
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                              000007fefd388ef0 6 bytes JMP 000007fffd300148
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                          000007fefd39af60 5 bytes JMP 000007fffd300110
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                           000007fefd8589f0 8 bytes JMP 000007fffd3001f0
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                         000007fefd85be50 8 bytes JMP 000007fffd3001b8
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\ole32.dll!CoCreateInstance                                                 000007fefdfb7490 11 bytes JMP 000007fffd300228
.text  C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.EXE[3832] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                000007fefdfcbf00 7 bytes JMP 000007fffd300260
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                               0000000076411f0e 7 bytes JMP 0000000171f93d10
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                 0000000076415bad 7 bytes JMP 0000000171f946b0
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                 0000000076421409 7 bytes JMP 0000000171f94050
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                000000007642ea45 7 bytes JMP 0000000171f93d00
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                           000000007643a2fd 1 byte [62]
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                        00000000764b8e24 7 bytes JMP 0000000171f937c0
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                        00000000764b8ea9 5 bytes JMP 0000000171f93870
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                          00000000764b91ff 5 bytes JMP 0000000171f937d0
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                             0000000076211d29 5 bytes JMP 0000000171f93780
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                           0000000076211dd7 5 bytes JMP 0000000171f93740
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                               0000000076212ab1 5 bytes JMP 0000000171f93880
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                  0000000076212d17 5 bytes JMP 0000000171f93560
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                  00000000769e8a29 5 bytes JMP 0000000171f92c50
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                              00000000769f4572 5 bytes JMP 0000000171f934e0
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                              0000000076a0e567 5 bytes JMP 0000000171f93550
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                                         0000000076a307d7 5 bytes JMP 0000000171f92a60
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                       0000000076a47a5c 5 bytes JMP 0000000171f934d0
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                          000000007601e96b 5 bytes JMP 0000000171f92d70
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                            000000007601eba5 5 bytes JMP 0000000171f92d80
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                 0000000076885ea5 5 bytes JMP 0000000171f92c10
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                  00000000768b9d0b 5 bytes JMP 0000000171f92ba0
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                         00000000763f1465 2 bytes [3F, 76]
.text  C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe[3872] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                        00000000763f14bb 2 bytes [3F, 76]
.text  ...                                                                                                                                                                       * 2
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                                       0000000076411f0e 7 bytes JMP 0000000171f93d10
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                         0000000076415bad 7 bytes JMP 0000000171f946b0
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                         0000000076421409 7 bytes JMP 0000000171f94050
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                        000000007642ea45 7 bytes JMP 0000000171f93d00
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                                   000000007643a2fd 1 byte [62]
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                                00000000764b8e24 7 bytes JMP 0000000171f937c0
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                                00000000764b8ea9 5 bytes JMP 0000000171f93870
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                                  00000000764b91ff 5 bytes JMP 0000000171f937d0
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                                     0000000076211d29 5 bytes JMP 0000000171f93780
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                                   0000000076211dd7 5 bytes JMP 0000000171f93740
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                       0000000076212ab1 5 bytes JMP 0000000171f93880
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                          0000000076212d17 5 bytes JMP 0000000171f93560
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                                  000000007601e96b 5 bytes JMP 0000000171f92d70
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                                    000000007601eba5 5 bytes JMP 0000000171f92d80
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                          00000000769e8a29 5 bytes JMP 0000000171f92c50
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                                      00000000769f4572 5 bytes JMP 0000000171f934e0
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                                      0000000076a0e567 5 bytes JMP 0000000171f93550
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                                                                 0000000076a307d7 5 bytes JMP 0000000171f92a60
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                               0000000076a47a5c 5 bytes JMP 0000000171f934d0
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                                         0000000076885ea5 5 bytes JMP 0000000171f92c10
.text  C:\Users\Kamil\Downloads\TSMApplication.exe[3904] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                          00000000768b9d0b 5 bytes JMP 0000000171f92ba0
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\KERNEL32.dll!RegSetValueExW                                                                                            000000007711a400 7 bytes JMP 000000016fff0228
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW                                                                                          0000000077123f20 5 bytes JMP 000000016fff0180
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW                                                                                           000000007713ffb0 5 bytes JMP 000000016fff01b8
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW                                                                                     000000007714f2e0 5 bytes JMP 000000016fff0110
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                                                                      000000007716ef8d 1 byte [62]
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx                                                                                   0000000077179a30 7 bytes JMP 000000016fff00d8
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation                                                                                   00000000771894c0 5 bytes JMP 000000016fff0148
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\KERNEL32.dll!RegSetValueExA                                                                                            00000000771a87e0 7 bytes JMP 000000016fff01f0
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                                             000007fefd382db0 5 bytes JMP 000007fffd370180
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                                        000007fefd3837d0 7 bytes JMP 000007fffd3700d8
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                                          000007fefd388ef0 6 bytes JMP 000007fffd370148
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                                      000007fefd39af60 5 bytes JMP 000007fffd370110
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                                       000007fefd8589f0 8 bytes JMP 000007fffd3701f0
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                                     000007fefd85be50 8 bytes JMP 000007fffd3701b8
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                             000007fefdfb7490 11 bytes JMP 000007fffd370228
.text  C:\Dolby PCEE4\pcee4.exe[3952] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                                            000007fefdfcbf00 7 bytes JMP 000007fffd370260
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                                0000000076411f0e 7 bytes JMP 0000000171f93d10
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                  0000000076415bad 7 bytes JMP 0000000171f946b0
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                  0000000076421409 7 bytes JMP 0000000171f94050
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                 000000007642ea45 7 bytes JMP 0000000171f93d00
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                            000000007643a2fd 1 byte [62]
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                         00000000764b8e24 7 bytes JMP 0000000171f937c0
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                         00000000764b8ea9 5 bytes JMP 0000000171f93870
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                           00000000764b91ff 5 bytes JMP 0000000171f937d0
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                              0000000076211d29 5 bytes JMP 0000000171f93780
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                            0000000076211dd7 5 bytes JMP 0000000171f93740
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                0000000076212ab1 5 bytes JMP 0000000171f93880
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                   0000000076212d17 5 bytes JMP 0000000171f93560
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                           000000007601e96b 5 bytes JMP 0000000171f92d70
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                             000000007601eba5 5 bytes JMP 0000000171f92d80
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                   00000000769e8a29 5 bytes JMP 0000000171f92c50
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                               00000000769f4572 5 bytes JMP 0000000171f934e0
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                               0000000076a0e567 5 bytes JMP 0000000171f93550
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                                                          0000000076a307d7 5 bytes JMP 0000000171f92a60
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                        0000000076a47a5c 5 bytes JMP 0000000171f934d0
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                                  0000000076885ea5 5 bytes JMP 0000000171f92c10
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                   00000000768b9d0b 5 bytes JMP 0000000171f92ba0
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                          00000000763f1465 2 bytes [3F, 76]
.text  C:\Program Files (x86)\Launch Manager\LManager.exe[3992] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                         00000000763f14bb 2 bytes [3F, 76]
.text  ...                                                                                                                                                                       * 2
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW          0000000076411f0e 7 bytes JMP 0000000171f93d10
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\kernel32.dll!RegSetValueExW            0000000076415bad 7 bytes JMP 0000000171f946b0
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\kernel32.dll!RegSetValueExA            0000000076421409 7 bytes JMP 0000000171f94050
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW           000000007642ea45 7 bytes JMP 0000000171f93d00
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112      000000007643a2fd 1 byte [62]
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx   00000000764b8e24 7 bytes JMP 0000000171f937c0
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation   00000000764b8ea9 5 bytes JMP 0000000171f93870
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW     00000000764b91ff 5 bytes JMP 0000000171f937d0
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW        0000000076211d29 5 bytes JMP 0000000171f93780
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW      0000000076211dd7 5 bytes JMP 0000000171f93740
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW          0000000076212ab1 5 bytes JMP 0000000171f93880
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary             0000000076212d17 5 bytes JMP 0000000171f93560
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList     000000007601e96b 5 bytes JMP 0000000171f92d70
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo       000000007601eba5 5 bytes JMP 0000000171f92d80
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\USER32.dll!CreateWindowExW             00000000769e8a29 5 bytes JMP 0000000171f92c50
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA         00000000769f4572 5 bytes JMP 0000000171f934e0
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW         0000000076a0e567 5 bytes JMP 0000000171f93550
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW    0000000076a307d7 5 bytes JMP 0000000171f92a60
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo  0000000076a47a5c 5 bytes JMP 0000000171f934d0
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket            0000000076885ea5 5 bytes JMP 0000000171f92c10
.text  C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[4000] C:\Windows\syswow64\ole32.dll!CoCreateInstance             00000000768b9d0b 5 bytes JMP 0000000171f92ba0
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                                 0000000076411f0e 7 bytes JMP 0000000171f93d10
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                   0000000076415bad 7 bytes JMP 0000000171f946b0
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter                                                      0000000076418791 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                   0000000076421409 7 bytes JMP 0000000171f94050
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                  000000007642ea45 7 bytes JMP 0000000171f93d00
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                             000000007643a2fd 1 byte [62]
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                          00000000764b8e24 7 bytes JMP 0000000171f937c0
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                          00000000764b8ea9 5 bytes JMP 0000000171f93870
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                            00000000764b91ff 5 bytes JMP 0000000171f937d0
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                               0000000076211d29 5 bytes JMP 0000000171f93780
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                             0000000076211dd7 5 bytes JMP 0000000171f93740
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                 0000000076212ab1 5 bytes JMP 0000000171f93880
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                    0000000076212d17 5 bytes JMP 0000000171f93560
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                            000000007601e96b 5 bytes JMP 0000000171f92d70
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                              000000007601eba5 5 bytes JMP 0000000171f92d80
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                    00000000769e8a29 5 bytes JMP 0000000171f92c50
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                                00000000769f4572 5 bytes JMP 0000000171f934e0
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                                0000000076a0e567 5 bytes JMP 0000000171f93550
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                                                           0000000076a307d7 5 bytes JMP 0000000171f92a60
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                         0000000076a47a5c 5 bytes JMP 0000000171f934d0
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                           00000000763f1465 2 bytes [3F, 76]
.text  C:\Program Files\AVAST Software\Avast\avastui.exe[1976] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                          00000000763f14bb 2 bytes [3F, 76]
.text  ...                                                                                                                                                                       * 2
.text  C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3564] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                   000007fefd382db0 5 bytes JMP 000007fffd370180
.text  C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3564] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                              000007fefd3837d0 7 bytes JMP 000007fffd3700d8
.text  C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3564] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                000007fefd388ef0 6 bytes JMP 000007fffd370148
.text  C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3564] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                            000007fefd39af60 5 bytes JMP 000007fffd370110
.text  C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3564] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                             000007fefd8589f0 8 bytes JMP 000007fffd3701f0
.text  C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3564] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                           000007fefd85be50 8 bytes JMP 000007fffd3701b8
.text  C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3564] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                   000007fefdfb7490 11 bytes JMP 000007fffd370228
.text  C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe[3564] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                  000007fefdfcbf00 7 bytes JMP 000007fffd370260
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                                0000000076411f0e 7 bytes JMP 0000000171f93d10
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                  0000000076415bad 7 bytes JMP 0000000171f946b0
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                  0000000076421409 7 bytes JMP 0000000171f94050
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                 000000007642ea45 7 bytes JMP 0000000171f93d00
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                            000000007643a2fd 1 byte [62]
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                         00000000764b8e24 7 bytes JMP 0000000171f937c0
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                         00000000764b8ea9 5 bytes JMP 0000000171f93870
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                           00000000764b91ff 5 bytes JMP 0000000171f937d0
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                              0000000076211d29 5 bytes JMP 0000000171f93780
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                            0000000076211dd7 5 bytes JMP 0000000171f93740
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                0000000076212ab1 5 bytes JMP 0000000171f93880
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                   0000000076212d17 5 bytes JMP 0000000171f93560
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                   00000000769e8a29 5 bytes JMP 0000000171f92c50
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                               00000000769f4572 5 bytes JMP 0000000171f934e0
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                               0000000076a0e567 5 bytes JMP 0000000171f93550
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                                                          0000000076a307d7 5 bytes JMP 0000000171f92a60
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                        0000000076a47a5c 5 bytes JMP 0000000171f934d0
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                           000000007601e96b 5 bytes JMP 0000000171f92d70
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                             000000007601eba5 5 bytes JMP 0000000171f92d80
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                                                  0000000076885ea5 5 bytes JMP 0000000171f92c10
.text  C:\Program Files (x86)\Launch Manager\LMworker.exe[3748] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                                                   00000000768b9d0b 5 bytes JMP 0000000171f92ba0
.text  C:\Windows\system32\wbem\unsecapp.exe[3496] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                                000007fefd382db0 5 bytes JMP 000007fffd370180
.text  C:\Windows\system32\wbem\unsecapp.exe[3496] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                           000007fefd3837d0 7 bytes JMP 000007fffd3700d8
.text  C:\Windows\system32\wbem\unsecapp.exe[3496] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                             000007fefd388ef0 6 bytes JMP 000007fffd370148
.text  C:\Windows\system32\wbem\unsecapp.exe[3496] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                         000007fefd39af60 5 bytes JMP 000007fffd370110
.text  C:\Windows\system32\wbem\unsecapp.exe[3496] C:\Windows\system32\ole32.dll!CoCreateInstance                                                                                000007fefdfb7490 11 bytes JMP 000007fffd370228
.text  C:\Windows\system32\wbem\unsecapp.exe[3496] C:\Windows\system32\ole32.dll!CoSetProxyBlanket                                                                               000007fefdfcbf00 7 bytes JMP 000007fffd370260
.text  C:\Windows\system32\wbem\unsecapp.exe[3496] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                          000007fefd8589f0 8 bytes JMP 000007fffd3701f0
.text  C:\Windows\system32\wbem\unsecapp.exe[3496] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                        000007fefd85be50 8 bytes JMP 000007fffd3701b8
.text  C:\Program Files\Elantech\ETDCtrlHelper.exe[3560] C:\Windows\system32\kernel32.dll!RegSetValueExW                                                                         000000007711a400 7 bytes JMP 000000016fff0228
.text  C:\Program Files\Elantech\ETDCtrlHelper.exe[3560] C:\Windows\system32\kernel32.dll!RegQueryValueExW                                                                       0000000077123f20 5 bytes JMP 000000016fff0180
.text  C:\Program Files\Elantech\ETDCtrlHelper.exe[3560] C:\Windows\system32\kernel32.dll!RegDeleteValueW                                                                        000000007713ffb0 5 bytes JMP 000000016fff01b8
.text  C:\Program Files\Elantech\ETDCtrlHelper.exe[3560] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW                                                                  000000007714f2e0 5 bytes JMP 000000016fff0110
.text  C:\Program Files\Elantech\ETDCtrlHelper.exe[3560] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                   000000007716ef8d 1 byte [62]
.text  C:\Program Files\Elantech\ETDCtrlHelper.exe[3560] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx                                                                0000000077179a30 7 bytes JMP 000000016fff00d8
.text  C:\Program Files\Elantech\ETDCtrlHelper.exe[3560] C:\Windows\system32\kernel32.dll!K32GetModuleInformation                                                                00000000771894c0 5 bytes JMP 000000016fff0148
.text  C:\Program Files\Elantech\ETDCtrlHelper.exe[3560] C:\Windows\system32\kernel32.dll!RegSetValueExA                                                                         00000000771a87e0 7 bytes JMP 000000016fff01f0
.text  C:\Program Files\Elantech\ETDCtrlHelper.exe[3560] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                          000007fefd382db0 5 bytes JMP 000007fffd370180
.text  C:\Program Files\Elantech\ETDCtrlHelper.exe[3560] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                     000007fefd3837d0 7 bytes JMP 000007fffd3700d8
.text  C:\Program Files\Elantech\ETDCtrlHelper.exe[3560] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                       000007fefd388ef0 6 bytes JMP 000007fffd370148
.text  C:\Program Files\Elantech\ETDCtrlHelper.exe[3560] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                                   000007fefd39af60 5 bytes JMP 000007fffd370110
.text  C:\Program Files\Elantech\ETDCtrlHelper.exe[3560] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                    000007fefd8589f0 8 bytes JMP 000007fffd3701f0
.text  C:\Program Files\Elantech\ETDCtrlHelper.exe[3560] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                                  000007fefd85be50 8 bytes JMP 000007fffd3701b8
.text  C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe[1684] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                           000000007643a2fd 1 byte [62]
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!LdrUnloadDll                                                                          0000000077253b10 6 bytes {NOP ; JMP 0xffffffff88fdcc4c}
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll                                                                            0000000077257ac0 6 bytes {NOP ; JMP 0xffffffff88fd88e4}
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\system32\KERNEL32.dll!RegSetValueExW                                                                     000000007711a400 7 bytes JMP 000000016fff0228
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW                                                                   0000000077123f20 5 bytes JMP 000000016fff0180
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW                                                                    000000007713ffb0 5 bytes JMP 000000016fff01b8
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW                                                              000000007714f2e0 5 bytes JMP 000000016fff0110
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                                                               000000007716ef8d 1 byte [62]
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx                                                            0000000077179a30 7 bytes JMP 000000016fff00d8
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation                                                            00000000771894c0 5 bytes JMP 000000016fff0148
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\system32\KERNEL32.dll!RegSetValueExA                                                                     00000000771a87e0 7 bytes JMP 000000016fff01f0
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\system32\KERNELBASE.dll!FreeLibrary                                                                      000007fefd382db0 5 bytes JMP 000007fffd320180
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW                                                                 000007fefd3837d0 7 bytes JMP 000007fffd3200d8
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW                                                                   000007fefd388ef0 6 bytes JMP 000007fffd320148
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW                                                               000007fefd39af60 5 bytes JMP 000007fffd320110
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo                                                                000007fefd8589f0 8 bytes JMP 000007fffd3201f0
.text  C:\Program Files\Internet Explorer\iexplore.exe[3784] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList                                                              000007fefd85be50 8 bytes JMP 000007fffd3201b8
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                                      000000007744c4dd 5 bytes JMP 00000001000301f8
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                                    0000000077451287 5 bytes JMP 00000001000303fc
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW                                                             0000000076411f0e 7 bytes JMP 0000000171f93d10
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW                                                               0000000076415bad 7 bytes JMP 0000000171f946b0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA                                                               0000000076421409 7 bytes JMP 0000000171f94050
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW                                                              000000007642ea45 7 bytes JMP 0000000171f93d00
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                                                         000000007643a2fd 1 byte [62]
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx                                                      00000000764b8e24 7 bytes JMP 0000000171f937c0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation                                                      00000000764b8ea9 5 bytes JMP 0000000171f93870
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW                                                        00000000764b91ff 5 bytes JMP 0000000171f937d0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                           0000000076211d29 5 bytes JMP 0000000171f93780
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                         0000000076211dd7 5 bytes JMP 0000000171f93740
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                             0000000076212ab1 5 bytes JMP 0000000171f93880
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                0000000076212d17 5 bytes JMP 0000000171f93560
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\user32.DLL!CreateWindowExW                                                                00000000769e8a29 5 bytes JMP 0000000171f92c50
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesA                                                            00000000769f4572 5 bytes JMP 0000000171f934e0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesW                                                            0000000076a0e567 5 bytes JMP 0000000171f93550
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\user32.DLL!ChangeDisplaySettingsExW                                                       0000000076a307d7 5 bytes JMP 0000000171f92a60
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\user32.DLL!DisplayConfigGetDeviceInfo                                                     0000000076a47a5c 5 bytes JMP 0000000171f934d0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                        000000007601e96b 5 bytes JMP 0000000171f92d70
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                          000000007601eba5 5 bytes JMP 0000000171f92d80
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                       00000000763f1465 2 bytes [3F, 76]
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4728] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                      00000000763f14bb 2 bytes [3F, 76]
.text  ...                                                                                                                                                                       * 2
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW                                     0000000076411f0e 7 bytes JMP 0000000171f93d10
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW                                       0000000076415bad 7 bytes JMP 0000000171f946b0
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA                                       0000000076421409 7 bytes JMP 0000000171f94050
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW                                      000000007642ea45 7 bytes JMP 0000000171f93d00
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                                 000000007643a2fd 1 byte [62]
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx                              00000000764b8e24 7 bytes JMP 0000000171f937c0
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation                              00000000764b8ea9 5 bytes JMP 0000000171f93870
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW                                00000000764b91ff 5 bytes JMP 0000000171f937d0
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                   0000000076211d29 5 bytes JMP 0000000171f93780
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                 0000000076211dd7 5 bytes JMP 0000000171f93740
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                     0000000076212ab1 5 bytes JMP 0000000171f93880
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                        0000000076212d17 5 bytes JMP 0000000171f93560
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                000000007601e96b 5 bytes JMP 0000000171f92d70
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                  000000007601eba5 5 bytes JMP 0000000171f92d80
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                        00000000769e8a29 5 bytes JMP 0000000171f92c50
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                    00000000769f4572 5 bytes JMP 0000000171f934e0
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                    0000000076a0e567 5 bytes JMP 0000000171f93550
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                               0000000076a307d7 5 bytes JMP 0000000171f92a60
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                             0000000076a47a5c 5 bytes JMP 0000000171f934d0
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                       0000000076885ea5 5 bytes JMP 0000000171f92c10
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe[4768] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                        00000000768b9d0b 5 bytes JMP 0000000171f92ba0
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW                                  0000000076411f0e 7 bytes JMP 0000000171f93d10
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW                                    0000000076415bad 7 bytes JMP 0000000171f946b0
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA                                    0000000076421409 7 bytes JMP 0000000171f94050
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW                                   000000007642ea45 7 bytes JMP 0000000171f93d00
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                              000000007643a2fd 1 byte [62]
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx                           00000000764b8e24 7 bytes JMP 0000000171f937c0
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation                           00000000764b8ea9 5 bytes JMP 0000000171f93870
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW                             00000000764b91ff 5 bytes JMP 0000000171f937d0
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                0000000076211d29 5 bytes JMP 0000000171f93780
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                              0000000076211dd7 5 bytes JMP 0000000171f93740
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                  0000000076212ab1 5 bytes JMP 0000000171f93880
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                     0000000076212d17 5 bytes JMP 0000000171f93560
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                             000000007601e96b 5 bytes JMP 0000000171f92d70
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                               000000007601eba5 5 bytes JMP 0000000171f92d80
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                     00000000769e8a29 5 bytes JMP 0000000171f92c50
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                 00000000769f4572 5 bytes JMP 0000000171f934e0
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                 0000000076a0e567 5 bytes JMP 0000000171f93550
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                            0000000076a307d7 5 bytes JMP 0000000171f92a60
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                          0000000076a47a5c 5 bytes JMP 0000000171f934d0
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket                                    0000000076885ea5 5 bytes JMP 0000000171f92c10
.text  C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe[4784] C:\Windows\syswow64\ole32.dll!CoCreateInstance                                     00000000768b9d0b 5 bytes JMP 0000000171f92ba0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                                      000000007744c4dd 5 bytes JMP 00000001000301f8
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                                    0000000077451287 5 bytes JMP 00000001000303fc
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW                                                             0000000076411f0e 7 bytes JMP 0000000171f93d10
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW                                                               0000000076415bad 7 bytes JMP 0000000171f946b0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA                                                               0000000076421409 7 bytes JMP 0000000171f94050
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW                                                              000000007642ea45 7 bytes JMP 0000000171f93d00
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                                                         000000007643a2fd 1 byte [62]
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx                                                      00000000764b8e24 7 bytes JMP 0000000171f937c0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation                                                      00000000764b8ea9 5 bytes JMP 0000000171f93870
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW                                                        00000000764b91ff 5 bytes JMP 0000000171f937d0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                           0000000076211d29 5 bytes JMP 0000000171f93780
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                         0000000076211dd7 5 bytes JMP 0000000171f93740
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                             0000000076212ab1 5 bytes JMP 0000000171f93880
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                0000000076212d17 5 bytes JMP 0000000171f93560
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\user32.DLL!CreateWindowExW                                                                00000000769e8a29 5 bytes JMP 0000000171f92c50
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesA                                                            00000000769f4572 5 bytes JMP 0000000171f934e0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesW                                                            0000000076a0e567 5 bytes JMP 0000000171f93550
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\user32.DLL!ChangeDisplaySettingsExW                                                       0000000076a307d7 5 bytes JMP 0000000171f92a60
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\user32.DLL!DisplayConfigGetDeviceInfo                                                     0000000076a47a5c 5 bytes JMP 0000000171f934d0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                        000000007601e96b 5 bytes JMP 0000000171f92d70
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                          000000007601eba5 5 bytes JMP 0000000171f92d80
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                       00000000763f1465 2 bytes [3F, 76]
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[4168] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                      00000000763f14bb 2 bytes [3F, 76]
.text  ...                                                                                                                                                                       * 2
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                                      000000007744c4dd 5 bytes JMP 00000001000301f8
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\SysWOW64\ntdll.dll!LdrUnloadDll                                                                    0000000077451287 5 bytes JMP 00000001000303fc
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW                                                             0000000076411f0e 7 bytes JMP 0000000171f93d10
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW                                                               0000000076415bad 7 bytes JMP 0000000171f946b0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA                                                               0000000076421409 7 bytes JMP 0000000171f94050
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW                                                              000000007642ea45 7 bytes JMP 0000000171f93d00
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112                                                         000000007643a2fd 1 byte [62]
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx                                                      00000000764b8e24 7 bytes JMP 0000000171f937c0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation                                                      00000000764b8ea9 5 bytes JMP 0000000171f93870
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW                                                        00000000764b91ff 5 bytes JMP 0000000171f937d0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                           0000000076211d29 5 bytes JMP 0000000171f93780
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                         0000000076211dd7 5 bytes JMP 0000000171f93740
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                             0000000076212ab1 5 bytes JMP 0000000171f93880
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                0000000076212d17 5 bytes JMP 0000000171f93560
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\user32.DLL!CreateWindowExW                                                                00000000769e8a29 5 bytes JMP 0000000171f92c50
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesA                                                            00000000769f4572 5 bytes JMP 0000000171f934e0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesW                                                            0000000076a0e567 5 bytes JMP 0000000171f93550
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\user32.DLL!ChangeDisplaySettingsExW                                                       0000000076a307d7 5 bytes JMP 0000000171f92a60
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\user32.DLL!DisplayConfigGetDeviceInfo                                                     0000000076a47a5c 5 bytes JMP 0000000171f934d0
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                        000000007601e96b 5 bytes JMP 0000000171f92d70
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                          000000007601eba5 5 bytes JMP 0000000171f92d80
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                                       00000000763f1465 2 bytes [3F, 76]
.text  C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE[3020] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                                      00000000763f14bb 2 bytes [3F, 76]
.text  ...                                                                                                                                                                       * 2
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW                                                                               0000000076411f0e 7 bytes JMP 0000000171f93d10
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\kernel32.dll!RegSetValueExW                                                                                 0000000076415bad 7 bytes JMP 0000000171f946b0
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\kernel32.dll!RegSetValueExA                                                                                 0000000076421409 7 bytes JMP 0000000171f94050
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW                                                                                000000007642ea45 7 bytes JMP 0000000171f93d00
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                                           000000007643a2fd 1 byte [62]
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx                                                                        00000000764b8e24 7 bytes JMP 0000000171f937c0
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation                                                                        00000000764b8ea9 5 bytes JMP 0000000171f93870
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW                                                                          00000000764b91ff 5 bytes JMP 0000000171f937d0
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW                                                                             0000000076211d29 5 bytes JMP 0000000171f93780
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW                                                                           0000000076211dd7 5 bytes JMP 0000000171f93740
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW                                                                               0000000076212ab1 5 bytes JMP 0000000171f93880
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary                                                                                  0000000076212d17 5 bytes JMP 0000000171f93560
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList                                                                          000000007601e96b 5 bytes JMP 0000000171f92d70
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo                                                                            000000007601eba5 5 bytes JMP 0000000171f92d80
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\USER32.dll!CreateWindowExW                                                                                  00000000769e8a29 5 bytes JMP 0000000171f92c50
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA                                                                              00000000769f4572 5 bytes JMP 0000000171f934e0
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW                                                                              0000000076a0e567 5 bytes JMP 0000000171f93550
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW                                                                         0000000076a307d7 5 bytes JMP 0000000171f92a60
.text  C:\Users\Kamil\Desktop\ijgd35kp.exe[3036] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo                                                                       0000000076a47a5c 5 bytes JMP 0000000171f934d0

---- Registry - GMER 2.1 ----

Reg    HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\08edb9f20b8a                                                                                               
Reg    HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\08edb9f20b8a (not active ControlSet)                                                                           

---- EOF - GMER 2.1 ----
