Teil 2 gmer
Code:
Alles auswählen Aufklappen ATTFilter
erv.exe[1576] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000753a8781 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077041401 2 bytes JMP 753cb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077041419 2 bytes JMP 753cb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077041431 2 bytes JMP 75448f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007704144a 2 bytes CALL 753a489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000770414dd 2 bytes JMP 75448822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000770414f5 2 bytes JMP 754489f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007704150d 2 bytes JMP 75448718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077041525 2 bytes JMP 75448ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007704153d 2 bytes JMP 753bfca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077041555 2 bytes JMP 753c68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007704156d 2 bytes JMP 75448fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077041585 2 bytes JMP 75448b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007704159d 2 bytes JMP 754486dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000770415b5 2 bytes JMP 753bfd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000770415cd 2 bytes JMP 753cb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000770416b2 2 bytes JMP 75448ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1576] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000770416bd 2 bytes JMP 75448671 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007766dc60 5 bytes JMP 00000000777d0460
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007766dcb0 5 bytes JMP 00000000777d0450
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007766de10 5 bytes JMP 00000000777d0370
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007766de60 5 bytes JMP 00000000777d0470
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007766de70 5 bytes JMP 00000000777d03e0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007766df20 5 bytes JMP 00000000777d0320
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007766df50 5 bytes JMP 00000000777d03b0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007766df70 5 bytes JMP 00000000777d0390
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007766dfb0 5 bytes JMP 00000000777d02e0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007766e030 5 bytes JMP 00000000777d02d0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007766e050 5 bytes JMP 00000000777d0310
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007766e090 5 bytes JMP 00000000777d03c0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007766e0e0 5 bytes JMP 00000000777d03f0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007766e240 5 bytes JMP 00000000777d0230
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007766e400 5 bytes JMP 00000000777d0480
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007766e430 5 bytes JMP 00000000777d03a0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007766e510 5 bytes JMP 00000000777d02f0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007766e520 5 bytes JMP 00000000777d0350
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007766e580 5 bytes JMP 00000000777d0290
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007766e610 5 bytes JMP 00000000777d02b0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007766e630 5 bytes JMP 00000000777d03d0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007766e640 5 bytes JMP 00000000777d0330
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007766e6b0 5 bytes JMP 00000000777d0410
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007766e6e0 5 bytes JMP 00000000777d0240
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007766e9a0 5 bytes JMP 00000000777d01e0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007766ea60 5 bytes JMP 00000000777d0250
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007766ea90 5 bytes JMP 00000000777d0490
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007766eaa0 5 bytes JMP 00000000777d04a0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007766ead0 5 bytes JMP 00000000777d0300
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007766eae0 5 bytes JMP 00000000777d0360
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007766eb40 5 bytes JMP 00000000777d02a0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007766eb90 5 bytes JMP 00000000777d02c0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007766ebc0 5 bytes JMP 00000000777d0380
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007766ebd0 5 bytes JMP 00000000777d0340
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007766eec0 5 bytes JMP 00000000777d0440
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007766f0c0 5 bytes JMP 00000000777d0260
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007766f0d0 5 bytes JMP 00000000777d0270
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007766f0e0 5 bytes JMP 00000000777d0400
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007766f2a0 5 bytes JMP 00000000777d01f0
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007766f2b0 5 bytes JMP 00000000777d0210
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007766f320 5 bytes JMP 00000000777d0200
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007766f380 5 bytes JMP 00000000777d0420
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007766f390 5 bytes JMP 00000000777d0430
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007766f3a0 5 bytes JMP 00000000777d0220
.text C:\Windows\System32\svchost.exe[1960] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007766f480 5 bytes JMP 00000000777d0280
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007766dc60 5 bytes JMP 00000000777d0460
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007766dcb0 5 bytes JMP 00000000777d0450
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007766de10 5 bytes JMP 00000000777d0370
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007766de60 5 bytes JMP 00000000777d0470
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007766de70 5 bytes JMP 00000000777d03e0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007766df20 5 bytes JMP 00000000777d0320
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007766df50 5 bytes JMP 00000000777d03b0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007766df70 5 bytes JMP 00000000777d0390
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007766dfb0 5 bytes JMP 00000000777d02e0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007766e030 5 bytes JMP 00000000777d02d0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007766e050 5 bytes JMP 00000000777d0310
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007766e090 5 bytes JMP 00000000777d03c0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007766e0e0 5 bytes JMP 00000000777d03f0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007766e240 5 bytes JMP 00000000777d0230
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007766e400 5 bytes JMP 00000000777d0480
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007766e430 5 bytes JMP 00000000777d03a0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007766e510 5 bytes JMP 00000000777d02f0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007766e520 5 bytes JMP 00000000777d0350
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007766e580 5 bytes JMP 00000000777d0290
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007766e610 5 bytes JMP 00000000777d02b0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007766e630 5 bytes JMP 00000000777d03d0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007766e640 5 bytes JMP 00000000777d0330
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007766e6b0 5 bytes JMP 00000000777d0410
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007766e6e0 5 bytes JMP 00000000777d0240
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007766e9a0 5 bytes JMP 00000000777d01e0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007766ea60 5 bytes JMP 00000000777d0250
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007766ea90 5 bytes JMP 00000000777d0490
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007766eaa0 5 bytes JMP 00000000777d04a0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007766ead0 5 bytes JMP 00000000777d0300
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007766eae0 5 bytes JMP 00000000777d0360
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007766eb40 5 bytes JMP 00000000777d02a0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007766eb90 5 bytes JMP 00000000777d02c0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007766ebc0 5 bytes JMP 00000000777d0380
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007766ebd0 5 bytes JMP 00000000777d0340
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007766eec0 5 bytes JMP 00000000777d0440
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007766f0c0 5 bytes JMP 00000000777d0260
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007766f0d0 5 bytes JMP 00000000777d0270
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007766f0e0 5 bytes JMP 00000000777d0400
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007766f2a0 5 bytes JMP 00000000777d01f0
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007766f2b0 5 bytes JMP 00000000777d0210
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007766f320 5 bytes JMP 00000000777d0200
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007766f380 5 bytes JMP 00000000777d0420
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007766f390 5 bytes JMP 00000000777d0430
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007766f3a0 5 bytes JMP 00000000777d0220
.text C:\Windows\Explorer.EXE[2328] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007766f480 5 bytes JMP 00000000777d0280
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007766dc60 5 bytes JMP 00000000777d0460
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007766dcb0 5 bytes JMP 00000000777d0450
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007766de10 5 bytes JMP 00000000777d0370
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007766de60 5 bytes JMP 00000000777d0470
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007766de70 5 bytes JMP 00000000777d03e0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007766df20 5 bytes JMP 00000000777d0320
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007766df50 5 bytes JMP 00000000777d03b0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007766df70 5 bytes JMP 00000000777d0390
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007766dfb0 5 bytes JMP 00000000777d02e0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007766e030 5 bytes JMP 00000000777d02d0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007766e050 5 bytes JMP 00000000777d0310
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007766e090 5 bytes JMP 00000000777d03c0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007766e0e0 5 bytes JMP 00000000777d03f0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007766e240 5 bytes JMP 00000000777d0230
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007766e400 5 bytes JMP 00000000777d0480
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007766e430 5 bytes JMP 00000000777d03a0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007766e510 5 bytes JMP 00000000777d02f0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007766e520 5 bytes JMP 00000000777d0350
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007766e580 5 bytes JMP 00000000777d0290
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007766e610 5 bytes JMP 00000000777d02b0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007766e630 5 bytes JMP 00000000777d03d0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007766e640 5 bytes JMP 00000000777d0330
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007766e6b0 5 bytes JMP 00000000777d0410
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007766e6e0 5 bytes JMP 00000000777d0240
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007766e9a0 5 bytes JMP 00000000777d01e0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007766ea60 5 bytes JMP 00000000777d0250
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007766ea90 5 bytes JMP 00000000777d0490
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007766eaa0 5 bytes JMP 00000000777d04a0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007766ead0 5 bytes JMP 00000000777d0300
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007766eae0 5 bytes JMP 00000000777d0360
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007766eb40 5 bytes JMP 00000000777d02a0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007766eb90 5 bytes JMP 00000000777d02c0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007766ebc0 5 bytes JMP 00000000777d0380
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007766ebd0 5 bytes JMP 00000000777d0340
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007766eec0 5 bytes JMP 00000000777d0440
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007766f0c0 5 bytes JMP 00000000777d0260
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007766f0d0 5 bytes JMP 00000000777d0270
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007766f0e0 5 bytes JMP 00000000777d0400
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007766f2a0 5 bytes JMP 00000000777d01f0
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007766f2b0 5 bytes JMP 00000000777d0210
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007766f320 5 bytes JMP 00000000777d0200
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007766f380 5 bytes JMP 00000000777d0420
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007766f390 5 bytes JMP 00000000777d0430
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007766f3a0 5 bytes JMP 00000000777d0220
.text C:\Windows\system32\svchost.exe[2500] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007766f480 5 bytes JMP 00000000777d0280
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3188] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000753a8781 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000077041401 2 bytes JMP 753cb21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000077041419 2 bytes JMP 753cb346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000077041431 2 bytes JMP 75448f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007704144a 2 bytes CALL 753a489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000770414dd 2 bytes JMP 75448822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000770414f5 2 bytes JMP 754489f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007704150d 2 bytes JMP 75448718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000077041525 2 bytes JMP 75448ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007704153d 2 bytes JMP 753bfca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000077041555 2 bytes JMP 753c68ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007704156d 2 bytes JMP 75448fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000077041585 2 bytes JMP 75448b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007704159d 2 bytes JMP 754486dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000770415b5 2 bytes JMP 753bfd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000770415cd 2 bytes JMP 753cb2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000770416b2 2 bytes JMP 75448ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\System Explorer\SystemExplorer.exe[2776] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000770416bd 2 bytes JMP 75448671 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007766dc60 5 bytes JMP 00000000777d0460
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007766dcb0 5 bytes JMP 00000000777d0450
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007766de10 5 bytes JMP 00000000777d0370
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007766de60 5 bytes JMP 00000000777d0470
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007766de70 5 bytes JMP 00000000777d03e0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007766df20 5 bytes JMP 00000000777d0320
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007766df50 5 bytes JMP 00000000777d03b0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007766df70 5 bytes JMP 00000000777d0390
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007766dfb0 5 bytes JMP 00000000777d02e0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007766e030 5 bytes JMP 00000000777d02d0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007766e050 5 bytes JMP 00000000777d0310
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007766e090 5 bytes JMP 00000000777d03c0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007766e0e0 5 bytes JMP 00000000777d03f0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007766e240 5 bytes JMP 00000000777d0230
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007766e400 5 bytes JMP 00000000777d0480
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007766e430 5 bytes JMP 00000000777d03a0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007766e510 5 bytes JMP 00000000777d02f0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007766e520 5 bytes JMP 00000000777d0350
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007766e580 5 bytes JMP 00000000777d0290
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007766e610 5 bytes JMP 00000000777d02b0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007766e630 5 bytes JMP 00000000777d03d0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007766e640 5 bytes JMP 00000000777d0330
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007766e6b0 5 bytes JMP 00000000777d0410
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007766e6e0 5 bytes JMP 00000000777d0240
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007766e9a0 5 bytes JMP 00000000777d01e0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007766ea60 5 bytes JMP 00000000777d0250
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007766ea90 5 bytes JMP 00000000777d0490
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007766eaa0 5 bytes JMP 00000000777d04a0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007766ead0 5 bytes JMP 00000000777d0300
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007766eae0 5 bytes JMP 00000000777d0360
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007766eb40 5 bytes JMP 00000000777d02a0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007766eb90 5 bytes JMP 00000000777d02c0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007766ebc0 5 bytes JMP 00000000777d0380
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007766ebd0 5 bytes JMP 00000000777d0340
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007766eec0 5 bytes JMP 00000000777d0440
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007766f0c0 5 bytes JMP 00000000777d0260
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007766f0d0 5 bytes JMP 00000000777d0270
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007766f0e0 5 bytes JMP 00000000777d0400
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007766f2a0 5 bytes JMP 00000000777d01f0
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007766f2b0 5 bytes JMP 00000000777d0210
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007766f320 5 bytes JMP 00000000777d0200
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007766f380 5 bytes JMP 00000000777d0420
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007766f390 5 bytes JMP 00000000777d0430
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007766f3a0 5 bytes JMP 00000000777d0220
.text C:\Windows\system32\SearchIndexer.exe[3120] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007766f480 5 bytes JMP 00000000777d0280
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 000000007766dc60 5 bytes JMP 00000000777d0460
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 000000007766dcb0 5 bytes JMP 00000000777d0450
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 000000007766de10 5 bytes JMP 00000000777d0370
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 000000007766de60 5 bytes JMP 00000000777d0470
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 000000007766de70 5 bytes JMP 00000000777d03e0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 000000007766df20 5 bytes JMP 00000000777d0320
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 000000007766df50 5 bytes JMP 00000000777d03b0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 000000007766df70 5 bytes JMP 00000000777d0390
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 000000007766dfb0 5 bytes JMP 00000000777d02e0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 000000007766e030 5 bytes JMP 00000000777d02d0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 000000007766e050 5 bytes JMP 00000000777d0310
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 000000007766e090 5 bytes JMP 00000000777d03c0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 000000007766e0e0 5 bytes JMP 00000000777d03f0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 000000007766e240 5 bytes JMP 00000000777d0230
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 000000007766e400 5 bytes JMP 00000000777d0480
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 000000007766e430 5 bytes JMP 00000000777d03a0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 000000007766e510 5 bytes JMP 00000000777d02f0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 000000007766e520 5 bytes JMP 00000000777d0350
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 000000007766e580 5 bytes JMP 00000000777d0290
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 000000007766e610 5 bytes JMP 00000000777d02b0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 000000007766e630 5 bytes JMP 00000000777d03d0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 000000007766e640 5 bytes JMP 00000000777d0330
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 000000007766e6b0 5 bytes JMP 00000000777d0410
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 000000007766e6e0 5 bytes JMP 00000000777d0240
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 000000007766e9a0 5 bytes JMP 00000000777d01e0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 000000007766ea60 5 bytes JMP 00000000777d0250
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 000000007766ea90 5 bytes JMP 00000000777d0490
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 000000007766eaa0 5 bytes JMP 00000000777d04a0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 000000007766ead0 5 bytes JMP 00000000777d0300
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 000000007766eae0 5 bytes JMP 00000000777d0360
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 000000007766eb40 5 bytes JMP 00000000777d02a0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 000000007766eb90 5 bytes JMP 00000000777d02c0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 000000007766ebc0 5 bytes JMP 00000000777d0380
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 000000007766ebd0 5 bytes JMP 00000000777d0340
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 000000007766eec0 5 bytes JMP 00000000777d0440
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 000000007766f0c0 5 bytes JMP 00000000777d0260
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 000000007766f0d0 5 bytes JMP 00000000777d0270
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 000000007766f0e0 5 bytes JMP 00000000777d0400
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 000000007766f2a0 5 bytes JMP 00000000777d01f0
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 000000007766f2b0 5 bytes JMP 00000000777d0210
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 000000007766f320 5 bytes JMP 00000000777d0200
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 000000007766f380 5 bytes JMP 00000000777d0420
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 000000007766f390 5 bytes JMP 00000000777d0430
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 000000007766f3a0 5 bytes JMP 00000000777d0220
.text C:\Windows\system32\AUDIODG.EXE[4628] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 000000007766f480 5 bytes JMP 00000000777d0280
---- EOF - GMER 2.1 ----