misteltoe | 19.09.2013 20:53 | Win7 infiziert, u.a. TR/ATRAPS.Gen2 (Trojaner) Liste der Anhänge anzeigen (Anzahl: 3) Hallo beisammen,
Die Anleitung zur Daten-Sammlung find ich gut. Spitze!
Meine 'Symptome':
- beim Browsen kam eine Meldung über Virus-Befall, die offensichtlich NICHT von meiner Antivirus-Programm. Ich weiß dann zwar, dass dieses Warn-Fenster der eigentliche Virus ist, weiß dann aber nichts Besseres anzufangen, als das Fenster durch einen CLick auf das kleine Kreuz-Symbol in der Ecke rechts oben zu schließen, was vermutlich GRUNDFALSCH ist ?!?
- jetzt sehe ich ein neues Icon a.d. Desktop: Antivirus Security Pro (ich nutze aber Avira)
- beim Hochfahren kommt jetzt jedes Mal die Avira-Meldung 'Real-Time Protection detected 2 viruses or unwanted programs. Access was denied.' Manchmal sind es drei Funde. Wenn ich auf 'remove' clicke, ... kommt eine weitere Meldung, die noch ein wenig verhängnisvoller anmutet sodass ich das nicht mehr mache. I.d. Vergangenheit hat mich das immer zu einem vollständigen Avira-Scan veranlasst, der nicht immer angeschlagen hat.
- als es mal anschlug kam der Hinweis auf TR/ATRAPS.Gen2
Habe drei Log-files erstellt:
- GMER
- Avria log
- FRST (259,5 KB groß, d.h. kann's weder pasten noch anhängen)
GMER Logfile: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-09-19 21:05:38
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST350041 rev.CC46 465,76GB
Running: gxi2zbsu.exe; Driver: C:\Users\Saturn\AppData\Local\Temp\kxdirpog.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 544 fffff80003203000 45 bytes [00, 10, 00, 00, 00, 00, 00, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 591 fffff8000320302f 16 bytes [00, 00, 00, 00, 00, 00, 00, ...]
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe[2128] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076071465 2 bytes [07, 76]
.text C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe[2128] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760714bb 2 bytes [07, 76]
.text ... * 2
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 000000007720091c 4 bytes [68, 90, CB, 90]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077200921 1 byte [C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 000000007721261d 6 bytes [68, AE, D2, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007721c4dd 6 bytes [68, BB, CC, 90, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077222ad3 6 bytes [68, F4, D2, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077244168 6 bytes [68, 3A, D3, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007724e695 6 bytes [68, 80, D3, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076244514 6 bytes [68, 23, CF, 90, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000762479b0 6 bytes [68, E2, CE, 90, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!GetDC 0000000074f472c4 4 bytes [68, 96, BE, 90]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!GetDC + 5 0000000074f472c9 1 byte [C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!ReleaseDC 0000000074f47446 6 bytes [68, 14, BF, 90, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!TranslateMessage 0000000074f47809 6 bytes [68, 95, A5, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000074f478e2 6 bytes [68, C4, 89, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000074f47bd3 6 bytes [68, EC, 89, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!GetWindowDC 0000000074f48048 4 bytes [68, D5, BE, 90]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 0000000074f4804d 1 byte [C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000074f48a65 6 bytes [68, B2, D5, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!RegisterClassExW 0000000074f4b17d 6 bytes [68, 4C, D6, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!RegisterClassExA 0000000074f4db98 6 bytes [68, 9E, D6, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000074f505ba 6 bytes [68, 14, 8A, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000074f50d32 6 bytes [68, E4, D4, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000074f51218 6 bytes [68, F7, 87, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!EndPaint 0000000074f51341 4 bytes [68, FB, BD, 90]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!EndPaint + 5 0000000074f51346 1 byte [C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000074f51361 4 bytes [68, 8D, BD, 90]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 0000000074f51366 1 byte [C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000074f52a8d 6 bytes [68, C5, 87, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!GetCapture 0000000074f52aac 6 bytes [68, 25, 89, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000074f53391 4 bytes [68, 3B, BE, 90]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 0000000074f53396 1 byte [C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!RegisterClassA 0000000074f5434b 1 byte [68]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!RegisterClassA + 2 0000000074f5434d 4 bytes {CALL RBP}
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000074f55f74 6 bytes [68, 3F, 8A, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000074f56222 6 bytes [68, E7, BF, 90, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!CallWindowProcA 0000000074f5792f 6 bytes [68, 2D, D5, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000074f57fbb 6 bytes [68, 0F, D4, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 0000000074f5810c 6 bytes [68, 9E, D4, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!DefFrameProcW 0000000074f585c1 6 bytes [68, C6, D3, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 0000000074f586b4 6 bytes [68, 58, D4, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!GetUpdateRect 0000000074f6d41f 6 bytes [68, 54, BF, 90, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!ReleaseCapture 0000000074f6ed49 6 bytes [68, D5, 88, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!SetCapture 0000000074f6ed56 4 bytes [68, 7B, 88, 8F]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!SetCapture + 5 0000000074f6ed5b 1 byte [C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000074f89854 6 bytes [68, 90, D2, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000074f89cfd 6 bytes [68, 3E, 88, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000074f89f1d 6 bytes [68, 77, A7, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000074fa87cb 4 bytes [68, 40, D2, 8F]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 0000000074fa87d0 1 byte [C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007528c592 6 bytes [68, A0, CF, 90, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000752c2538 6 bytes [68, 89, CF, 90, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076bc3918 6 bytes [68, 73, 67, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076bc4296 6 bytes [68, 72, 63, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076bc4406 6 bytes [68, CC, 67, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WS2_32.dll!send 0000000076bc6f01 6 bytes [68, AB, 67, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076bd7673 6 bytes [68, 02, 63, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000074e11884 6 bytes [68, 6F, 7E, 8F, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 00000000763d4282 6 bytes [68, AF, EC, 8E, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 00000000763d7079 6 bytes [68, 4F, EE, 8E, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000763d7ca6 6 bytes [68, 37, EA, 8E, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 00000000763d83dd 6 bytes [68, AF, E9, 8E, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000763e92e9 6 bytes [68, 23, EE, 8E, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WININET.dll!InternetReadFile 00000000763e972b 6 bytes [68, 1C, ED, 8E, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 00000000763fae2e 6 bytes [68, 4A, ED, 8E, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 000000007643ceff 6 bytes [68, E1, EA, 8E, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 000000007643d4f4 6 bytes [68, 19, EC, 8E, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007644d8b4 6 bytes [68, C9, ED, 8E, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000764a3169 6 bytes [68, 64, EC, 8E, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 00000000764a3222 6 bytes [68, 7D, EB, 8E, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 00000000764a32f2 6 bytes [68, 8C, EA, 8E, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000764a3595 6 bytes [68, F3, E9, 8E, 00, C3]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076071465 2 bytes [07, 76]
.text C:\Program Files (x86)\Sony\Media Gallery\ElbServer.exe[3444] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760714bb 2 bytes [07, 76]
.text ... * 2
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 000000007720091c 4 bytes [68, 90, CB, 25]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077200921 1 byte [C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 000000007721261d 6 bytes [68, AE, D2, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007721c4dd 6 bytes [68, BB, CC, 25, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077222ad3 6 bytes [68, F4, D2, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077244168 6 bytes [68, 3A, D3, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007724e695 6 bytes [68, 80, D3, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076244514 6 bytes [68, 23, CF, 25, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000762479b0 6 bytes [68, E2, CE, 25, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!GetDC 0000000074f472c4 4 bytes [68, 96, BE, 25]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!GetDC + 5 0000000074f472c9 1 byte [C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!ReleaseDC 0000000074f47446 6 bytes [68, 14, BF, 25, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!TranslateMessage 0000000074f47809 6 bytes [68, 95, A5, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000074f478e2 6 bytes [68, C4, 89, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000074f47bd3 6 bytes [68, EC, 89, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!GetWindowDC 0000000074f48048 4 bytes [68, D5, BE, 25]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 0000000074f4804d 1 byte [C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000074f48a65 6 bytes [68, B2, D5, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!RegisterClassExW 0000000074f4b17d 6 bytes [68, 4C, D6, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!RegisterClassExA 0000000074f4db98 6 bytes [68, 9E, D6, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000074f505ba 6 bytes [68, 14, 8A, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000074f50d32 6 bytes [68, E4, D4, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000074f51218 6 bytes [68, F7, 87, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!EndPaint 0000000074f51341 4 bytes [68, FB, BD, 25]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!EndPaint + 5 0000000074f51346 1 byte [C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000074f51361 4 bytes [68, 8D, BD, 25]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 0000000074f51366 1 byte [C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000074f52a8d 6 bytes [68, C5, 87, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!GetCapture 0000000074f52aac 6 bytes [68, 25, 89, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000074f53391 4 bytes [68, 3B, BE, 25]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 0000000074f53396 1 byte [C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!RegisterClassA 0000000074f5434b 1 byte [68]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!RegisterClassA + 2 0000000074f5434d 4 bytes {CALL RBP}
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000074f55f74 6 bytes [68, 3F, 8A, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000074f56222 6 bytes [68, E7, BF, 25, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!CallWindowProcA 0000000074f5792f 6 bytes [68, 2D, D5, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000074f57fbb 6 bytes [68, 0F, D4, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 0000000074f5810c 6 bytes [68, 9E, D4, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!DefFrameProcW 0000000074f585c1 6 bytes [68, C6, D3, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 0000000074f586b4 6 bytes [68, 58, D4, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!GetUpdateRect 0000000074f6d41f 6 bytes [68, 54, BF, 25, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!ReleaseCapture 0000000074f6ed49 6 bytes [68, D5, 88, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!SetCapture 0000000074f6ed56 4 bytes [68, 7B, 88, 24]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!SetCapture + 5 0000000074f6ed5b 1 byte [C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000074f89854 6 bytes [68, 90, D2, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000074f89cfd 6 bytes [68, 3E, 88, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000074f89f1d 6 bytes [68, 77, A7, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000074fa87cb 4 bytes [68, 40, D2, 24]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 0000000074fa87d0 1 byte [C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007528c592 6 bytes [68, A0, CF, 25, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000752c2538 6 bytes [68, 89, CF, 25, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076071465 2 bytes [07, 76]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760714bb 2 bytes [07, 76]
.text ... * 2
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076bc3918 6 bytes [68, 73, 67, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076bc4296 6 bytes [68, 72, 63, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076bc4406 6 bytes [68, CC, 67, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WS2_32.dll!send 0000000076bc6f01 6 bytes [68, AB, 67, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076bd7673 6 bytes [68, 02, 63, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000074e11884 6 bytes [68, 6F, 7E, 24, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 00000000763d4282 6 bytes [68, AF, EC, 23, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 00000000763d7079 6 bytes [68, 4F, EE, 23, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000763d7ca6 6 bytes [68, 37, EA, 23, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 00000000763d83dd 6 bytes [68, AF, E9, 23, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000763e92e9 6 bytes [68, 23, EE, 23, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WININET.dll!InternetReadFile 00000000763e972b 6 bytes [68, 1C, ED, 23, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 00000000763fae2e 6 bytes [68, 4A, ED, 23, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 000000007643ceff 6 bytes [68, E1, EA, 23, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 000000007643d4f4 6 bytes [68, 19, EC, 23, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007644d8b4 6 bytes [68, C9, ED, 23, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000764a3169 6 bytes [68, 64, EC, 23, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 00000000764a3222 6 bytes [68, 7D, EB, 23, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 00000000764a32f2 6 bytes [68, 8C, EA, 23, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000764a3595 6 bytes [68, F3, E9, 23, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\SysWOW64\WINMM.dll!PlaySoundW 00000000711a2ef2 6 bytes [68, DE, CF, 25, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\SysWOW64\WINMM.dll!waveOutWrite 00000000711a4f7b 6 bytes [68, 05, D0, 25, 00, C3]
.text C:\Windows\SysWOW64\RunDll32.exe[4092] C:\Windows\SysWOW64\WINMM.dll!PlaySound 00000000711c441d 6 bytes [68, B7, CF, 25, 00, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 000000007720091c 6 bytes [68, 90, CB, 27, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 000000007721261d 6 bytes [68, AE, D2, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007721c4dd 6 bytes [68, BB, CC, 27, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077222ad3 6 bytes [68, F4, D2, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077244168 6 bytes [68, 3A, D3, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007724e695 6 bytes [68, 80, D3, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\KERNEL32.dll!GetFileAttributesExW 0000000076244514 6 bytes [68, 23, CF, 27, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\KERNEL32.dll!ExitProcess 00000000762479b0 6 bytes [68, E2, CE, 27, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007528c592 6 bytes [68, A0, CF, 27, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000752c2538 6 bytes [68, 89, CF, 27, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!GetDC 0000000074f472c4 6 bytes [68, 96, BE, 27, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!ReleaseDC 0000000074f47446 6 bytes [68, 14, BF, 27, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!TranslateMessage 0000000074f47809 6 bytes [68, 95, A5, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000074f478e2 6 bytes [68, C4, 89, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000074f47bd3 6 bytes [68, EC, 89, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!GetWindowDC 0000000074f48048 6 bytes [68, D5, BE, 27, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000074f48a65 6 bytes [68, B2, D5, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!RegisterClassExW 0000000074f4b17d 6 bytes [68, 4C, D6, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!RegisterClassExA 0000000074f4db98 6 bytes [68, 9E, D6, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000074f505ba 6 bytes [68, 14, 8A, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000074f50d32 6 bytes [68, E4, D4, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000074f51218 6 bytes [68, F7, 87, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!EndPaint 0000000074f51341 6 bytes [68, FB, BD, 27, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000074f51361 6 bytes [68, 8D, BD, 27, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000074f52a8d 6 bytes [68, C5, 87, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!GetCapture 0000000074f52aac 6 bytes [68, 25, 89, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000074f53391 6 bytes [68, 3B, BE, 27, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!RegisterClassA 0000000074f5434b 1 byte [68]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!RegisterClassA + 2 0000000074f5434d 4 bytes {CALL RBP}
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000074f55f74 6 bytes [68, 3F, 8A, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000074f56222 6 bytes [68, E7, BF, 27, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!CallWindowProcA 0000000074f5792f 6 bytes [68, 2D, D5, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000074f57fbb 6 bytes [68, 0F, D4, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 0000000074f5810c 6 bytes [68, 9E, D4, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!DefFrameProcW 0000000074f585c1 6 bytes [68, C6, D3, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 0000000074f586b4 6 bytes [68, 58, D4, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!GetUpdateRect 0000000074f6d41f 6 bytes [68, 54, BF, 27, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!ReleaseCapture 0000000074f6ed49 6 bytes [68, D5, 88, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!SetCapture 0000000074f6ed56 6 bytes [68, 7B, 88, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000074f89854 6 bytes [68, 90, D2, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000074f89cfd 6 bytes [68, 3E, 88, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000074f89f1d 6 bytes [68, 77, A7, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000074fa87cb 6 bytes [68, 40, D2, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076bc3918 6 bytes [68, 73, 67, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076bc4296 6 bytes [68, 72, 63, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076bc4406 6 bytes [68, CC, 67, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WS2_32.dll!send 0000000076bc6f01 6 bytes [68, AB, 67, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076bd7673 6 bytes [68, 02, 63, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000074e11884 6 bytes [68, 6F, 7E, 26, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 00000000763d4282 6 bytes [68, AF, EC, 25, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 00000000763d7079 6 bytes [68, 4F, EE, 25, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000763d7ca6 6 bytes [68, 37, EA, 25, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 00000000763d83dd 6 bytes [68, AF, E9, 25, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000763e92e9 6 bytes [68, 23, EE, 25, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WININET.dll!InternetReadFile 00000000763e972b 6 bytes [68, 1C, ED, 25, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 00000000763fae2e 6 bytes [68, 4A, ED, 25, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 000000007643ceff 6 bytes [68, E1, EA, 25, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 000000007643d4f4 6 bytes [68, 19, EC, 25, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007644d8b4 6 bytes [68, C9, ED, 25, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000764a3169 6 bytes [68, 64, EC, 25, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 00000000764a3222 6 bytes [68, 7D, EB, 25, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 00000000764a32f2 6 bytes [68, 8C, EA, 25, 01, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[3396] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000764a3595 6 bytes [68, F3, E9, 25, 01, C3]
.text C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe[3656] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 000000007720091c 4 bytes [68, 90, CB, 4B]
.text C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe[3656] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077200921 1 byte [C3]
.text C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe[3656] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 000000007721261d 6 bytes [68, AE, D2, 4A, 00, C3]
.text C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe[3656] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007721c4dd 6 bytes [68, BB, CC, 4B, 00, C3]
.text C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe[3656] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077222ad3 6 bytes [68, F4, D2, 4A, 00, C3]
.text C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe[3656] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077244168 6 bytes [68, 3A, D3, 4A, 00, C3]
.text C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe[3656] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007724e695 6 bytes [68, 80, D3, 4A, 00, C3]
.text C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe[3656] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076244514 6 bytes [68, 23, CF, 4B, 00, C3]
.text C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe[3656] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000762479b0 6 bytes [68, E2, CE, 4B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 000000007720091c 4 bytes [68, 90, CB, 7C]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess + 5 0000000077200921 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 000000007721261d 6 bytes [68, AE, D2, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007721c4dd 6 bytes [68, BB, CC, 7C, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077222ad3 6 bytes [68, F4, D2, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077244168 6 bytes [68, 3A, D3, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007724e695 6 bytes [68, 80, D3, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076244514 6 bytes [68, 23, CF, 7C, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000762479b0 6 bytes [68, E2, CE, 7C, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007528c592 6 bytes [68, A0, CF, 7C, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000752c2538 6 bytes [68, 89, CF, 7C, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!GetDC 0000000074f472c4 4 bytes [68, 96, BE, 7C]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!GetDC + 5 0000000074f472c9 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!ReleaseDC 0000000074f47446 6 bytes [68, 14, BF, 7C, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!TranslateMessage 0000000074f47809 6 bytes [68, 95, A5, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000074f478e2 6 bytes [68, C4, 89, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000074f47bd3 6 bytes [68, EC, 89, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!GetWindowDC 0000000074f48048 4 bytes [68, D5, BE, 7C]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!GetWindowDC + 5 0000000074f4804d 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000074f48a65 6 bytes [68, B2, D5, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!RegisterClassExW 0000000074f4b17d 6 bytes [68, 4C, D6, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!RegisterClassExA 0000000074f4db98 6 bytes [68, 9E, D6, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000074f505ba 6 bytes [68, 14, 8A, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000074f50d32 6 bytes [68, E4, D4, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000074f51218 6 bytes [68, F7, 87, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!EndPaint 0000000074f51341 4 bytes [68, FB, BD, 7C]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!EndPaint + 5 0000000074f51346 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000074f51361 4 bytes [68, 8D, BD, 7C]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!BeginPaint + 5 0000000074f51366 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000074f52a8d 6 bytes [68, C5, 87, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!GetCapture 0000000074f52aac 6 bytes [68, 25, 89, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000074f53391 4 bytes [68, 3B, BE, 7C]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!GetDCEx + 5 0000000074f53396 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!RegisterClassA 0000000074f5434b 1 byte [68]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!RegisterClassA + 2 0000000074f5434d 4 bytes {CALL RBP}
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000074f55f74 6 bytes [68, 3F, 8A, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000074f56222 6 bytes [68, E7, BF, 7C, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!CallWindowProcA 0000000074f5792f 6 bytes [68, 2D, D5, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000074f57fbb 6 bytes [68, 0F, D4, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 0000000074f5810c 6 bytes [68, 9E, D4, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!DefFrameProcW 0000000074f585c1 6 bytes [68, C6, D3, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 0000000074f586b4 6 bytes [68, 58, D4, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!GetUpdateRect 0000000074f6d41f 6 bytes [68, 54, BF, 7C, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!ReleaseCapture 0000000074f6ed49 6 bytes [68, D5, 88, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!SetCapture 0000000074f6ed56 4 bytes [68, 7B, 88, 7B]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!SetCapture + 5 0000000074f6ed5b 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000074f89854 6 bytes [68, 90, D2, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000074f89cfd 6 bytes [68, 3E, 88, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000074f89f1d 6 bytes [68, 77, A7, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000074fa87cb 4 bytes [68, 40, D2, 7B]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\USER32.dll!OpenInputDesktop + 5 0000000074fa87d0 1 byte [C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 00000000763d4282 6 bytes [68, AF, EC, 7A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 00000000763d7079 6 bytes [68, 4F, EE, 7A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000763d7ca6 6 bytes [68, 37, EA, 7A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 00000000763d83dd 6 bytes [68, AF, E9, 7A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000763e92e9 6 bytes [68, 23, EE, 7A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WININET.dll!InternetReadFile 00000000763e972b 6 bytes [68, 1C, ED, 7A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 00000000763fae2e 6 bytes [68, 4A, ED, 7A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 000000007643ceff 6 bytes [68, E1, EA, 7A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 000000007643d4f4 6 bytes [68, 19, EC, 7A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007644d8b4 6 bytes [68, C9, ED, 7A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000764a3169 6 bytes [68, 64, EC, 7A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 00000000764a3222 6 bytes [68, 7D, EB, 7A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 00000000764a32f2 6 bytes [68, 8C, EA, 7A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000764a3595 6 bytes [68, F3, E9, 7A, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076bc3918 6 bytes [68, 73, 67, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076bc4296 6 bytes [68, 72, 63, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076bc4406 6 bytes [68, CC, 67, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WS2_32.dll!send 0000000076bc6f01 6 bytes [68, AB, 67, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076bd7673 6 bytes [68, 02, 63, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3584] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000074e11884 6 bytes [68, 6F, 7E, 7B, 00, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 000000007720091c 6 bytes [68, 90, CB, 28, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 000000007721261d 6 bytes [68, AE, D2, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007721c4dd 6 bytes [68, BB, CC, 28, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077222ad3 6 bytes [68, F4, D2, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077244168 6 bytes [68, 3A, D3, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007724e695 6 bytes [68, 80, D3, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076244514 6 bytes [68, 23, CF, 28, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000762479b0 6 bytes [68, E2, CE, 28, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!GetDC 0000000074f472c4 6 bytes [68, 96, BE, 28, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!ReleaseDC 0000000074f47446 6 bytes [68, 14, BF, 28, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!TranslateMessage 0000000074f47809 6 bytes [68, 95, A5, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000074f478e2 6 bytes [68, C4, 89, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000074f47bd3 6 bytes [68, EC, 89, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!GetWindowDC 0000000074f48048 6 bytes [68, D5, BE, 28, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000074f48a65 6 bytes [68, B2, D5, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!RegisterClassExW 0000000074f4b17d 6 bytes [68, 4C, D6, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!RegisterClassExA 0000000074f4db98 6 bytes [68, 9E, D6, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000074f505ba 6 bytes [68, 14, 8A, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000074f50d32 6 bytes [68, E4, D4, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000074f51218 6 bytes [68, F7, 87, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!EndPaint 0000000074f51341 6 bytes [68, FB, BD, 28, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000074f51361 6 bytes [68, 8D, BD, 28, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000074f52a8d 6 bytes [68, C5, 87, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!GetCapture 0000000074f52aac 6 bytes [68, 25, 89, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000074f53391 6 bytes [68, 3B, BE, 28, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!RegisterClassA 0000000074f5434b 1 byte [68]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!RegisterClassA + 2 0000000074f5434d 4 bytes {CALL RBP}
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000074f55f74 6 bytes [68, 3F, 8A, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000074f56222 6 bytes [68, E7, BF, 28, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!CallWindowProcA 0000000074f5792f 6 bytes [68, 2D, D5, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000074f57fbb 6 bytes [68, 0F, D4, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 0000000074f5810c 6 bytes [68, 9E, D4, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!DefFrameProcW 0000000074f585c1 6 bytes [68, C6, D3, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 0000000074f586b4 6 bytes [68, 58, D4, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!GetUpdateRect 0000000074f6d41f 6 bytes [68, 54, BF, 28, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!ReleaseCapture 0000000074f6ed49 6 bytes [68, D5, 88, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!SetCapture 0000000074f6ed56 6 bytes [68, 7B, 88, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000074f89854 6 bytes [68, 90, D2, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000074f89cfd 6 bytes [68, 3E, 88, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000074f89f1d 6 bytes [68, 77, A7, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000074fa87cb 6 bytes [68, 40, D2, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007528c592 6 bytes [68, A0, CF, 28, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000752c2538 6 bytes [68, 89, CF, 28, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076bc3918 6 bytes [68, 73, 67, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076bc4296 6 bytes [68, 72, 63, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076bc4406 6 bytes [68, CC, 67, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WS2_32.dll!send 0000000076bc6f01 6 bytes [68, AB, 67, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076bd7673 6 bytes [68, 02, 63, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000074e11884 6 bytes [68, 6F, 7E, 27, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 00000000763d4282 6 bytes [68, AF, EC, 26, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 00000000763d7079 6 bytes [68, 4F, EE, 26, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000763d7ca6 6 bytes [68, 37, EA, 26, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 00000000763d83dd 6 bytes [68, AF, E9, 26, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000763e92e9 6 bytes [68, 23, EE, 26, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WININET.dll!InternetReadFile 00000000763e972b 6 bytes [68, 1C, ED, 26, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 00000000763fae2e 6 bytes [68, 4A, ED, 26, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 000000007643ceff 6 bytes [68, E1, EA, 26, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 000000007643d4f4 6 bytes [68, 19, EC, 26, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007644d8b4 6 bytes [68, C9, ED, 26, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000764a3169 6 bytes [68, 64, EC, 26, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 00000000764a3222 6 bytes [68, 7D, EB, 26, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 00000000764a32f2 6 bytes [68, 8C, EA, 26, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000764a3595 6 bytes [68, F3, E9, 26, 02, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076071465 2 bytes [07, 76]
.text C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SHTtray.exe[3616] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760714bb 2 bytes [07, 76]
.text ... * 2
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\SysWOW64\ntdll.dll!NtCreateUserProcess 000000007720091c 6 bytes [68, 90, CB, 6F, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_W 000000007721261d 6 bytes [68, AE, D2, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 000000007721c4dd 6 bytes [68, BB, CC, 6F, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\SysWOW64\ntdll.dll!NtdllDefWindowProc_A 0000000077222ad3 6 bytes [68, F4, D2, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_W 0000000077244168 6 bytes [68, 3A, D3, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\SysWOW64\ntdll.dll!NtdllDialogWndProc_A 000000007724e695 6 bytes [68, 80, D3, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\kernel32.dll!GetFileAttributesExW 0000000076244514 6 bytes [68, 23, CF, 6F, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\kernel32.dll!ExitProcess 00000000762479b0 6 bytes [68, E2, CE, 6F, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserW 000000007528c592 6 bytes [68, A0, CF, 6F, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\ADVAPI32.dll!CreateProcessAsUserA 00000000752c2538 6 bytes [68, 89, CF, 6F, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!GetDC 0000000074f472c4 6 bytes [68, 96, BE, 6F, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!ReleaseDC 0000000074f47446 6 bytes [68, 14, BF, 6F, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!TranslateMessage 0000000074f47809 6 bytes [68, 95, A5, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000074f478e2 6 bytes [68, C4, 89, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000074f47bd3 6 bytes [68, EC, 89, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!GetWindowDC 0000000074f48048 6 bytes [68, D5, BE, 6F, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!RegisterClassW 0000000074f48a65 6 bytes [68, B2, D5, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!RegisterClassExW 0000000074f4b17d 6 bytes [68, 4C, D6, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!RegisterClassExA 0000000074f4db98 6 bytes [68, 9E, D6, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000074f505ba 6 bytes [68, 14, 8A, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!CallWindowProcW 0000000074f50d32 6 bytes [68, E4, D4, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!GetCursorPos 0000000074f51218 6 bytes [68, F7, 87, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!EndPaint 0000000074f51341 6 bytes [68, FB, BD, 6F, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!BeginPaint 0000000074f51361 6 bytes [68, 8D, BD, 6F, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!GetMessagePos 0000000074f52a8d 6 bytes [68, C5, 87, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!GetCapture 0000000074f52aac 6 bytes [68, 25, 89, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!GetDCEx 0000000074f53391 6 bytes [68, 3B, BE, 6F, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!RegisterClassA 0000000074f5434b 1 byte [68]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!RegisterClassA + 2 0000000074f5434d 4 bytes {CALL RBP}
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000074f55f74 6 bytes [68, 3F, 8A, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!GetUpdateRgn 0000000074f56222 6 bytes [68, E7, BF, 6F, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!CallWindowProcA 0000000074f5792f 6 bytes [68, 2D, D5, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!DefFrameProcA 0000000074f57fbb 6 bytes [68, 0F, D4, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!DefMDIChildProcA 0000000074f5810c 6 bytes [68, 9E, D4, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!DefFrameProcW 0000000074f585c1 6 bytes [68, C6, D3, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!DefMDIChildProcW 0000000074f586b4 6 bytes [68, 58, D4, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!GetUpdateRect 0000000074f6d41f 6 bytes [68, 54, BF, 6F, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!ReleaseCapture 0000000074f6ed49 6 bytes [68, D5, 88, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!SetCapture 0000000074f6ed56 6 bytes [68, 7B, 88, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!SwitchDesktop 0000000074f89854 6 bytes [68, 90, D2, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!SetCursorPos 0000000074f89cfd 6 bytes [68, 3E, 88, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!GetClipboardData 0000000074f89f1d 6 bytes [68, 77, A7, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\USER32.dll!OpenInputDesktop 0000000074fa87cb 6 bytes [68, 40, D2, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076071465 2 bytes [07, 76]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760714bb 2 bytes [07, 76]
.text ... * 2
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\CRYPT32.dll!PFXImportCertStore 0000000074e11884 6 bytes [68, 6F, 7E, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WININET.dll!InternetCloseHandle 00000000763d4282 6 bytes [68, AF, EC, 6D, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WININET.dll!HttpQueryInfoA 00000000763d7079 6 bytes [68, 4F, EE, 6D, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WININET.dll!HttpSendRequestW 00000000763d7ca6 6 bytes [68, 37, EA, 6D, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WININET.dll!HttpOpenRequestW 00000000763d83dd 6 bytes [68, AF, E9, 6D, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WININET.dll!InternetQueryDataAvailable 00000000763e92e9 6 bytes [68, 23, EE, 6D, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WININET.dll!InternetReadFile 00000000763e972b 6 bytes [68, 1C, ED, 6D, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WININET.dll!InternetReadFileExA 00000000763fae2e 6 bytes [68, 4A, ED, 6D, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WININET.dll!HttpSendRequestExW 000000007643ceff 6 bytes [68, E1, EA, 6D, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WININET.dll!HttpEndRequestA 000000007643d4f4 6 bytes [68, 19, EC, 6D, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WININET.dll!InternetSetFilePointer 000000007644d8b4 6 bytes [68, C9, ED, 6D, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WININET.dll!HttpEndRequestW 00000000764a3169 6 bytes [68, 64, EC, 6D, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WININET.dll!HttpSendRequestExA 00000000764a3222 6 bytes [68, 7D, EB, 6D, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WININET.dll!HttpSendRequestA 00000000764a32f2 6 bytes [68, 8C, EA, 6D, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WININET.dll!HttpOpenRequestA 00000000764a3595 6 bytes [68, F3, E9, 6D, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000076bc3918 6 bytes [68, 73, 67, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WS2_32.dll!getaddrinfo 0000000076bc4296 6 bytes [68, 72, 63, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000076bc4406 6 bytes [68, CC, 67, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WS2_32.dll!send 0000000076bc6f01 6 bytes [68, AB, 67, 6E, 03, C3]
.text C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe[3800] C:\Windows\syswow64\WS2_32.dll!gethostbyname 0000000076bd7673 6 bytes [68, 02, 63, 6E, 03, C3]
.text C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe[3540] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076071465 2 bytes [07, 76]
.text C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe[3540] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000760714bb 2 bytes [07, 76]
.text ... * 2
---- Threads - GMER 2.1 ----
Thread C:\Windows\Explorer.EXE [1844:4020] 0000000002bf5824
Thread C:\Windows\SysWOW64\RunDll32.exe [4092:4228] 00000000002568d7
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\18f46af9eb79
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\2c8158c875f4
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\2c8158c8cdc1
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\f07bcbe750a4
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\18f46af9eb79 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\2c8158c875f4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\2c8158c8cdc1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\f07bcbe750a4 (not active ControlSet)
---- EOF - GMER 2.1 ---- --- --- ---
Avira Antivirus Premium Updater
Complete product update
Creation time: Sonntag, 15. September 2013 22:47:22
Operating system:
Windows 7 Home Premium (Service Pack 1) [6.1.7601] 64 bit
Product information:
Product version: 13.0.0.4052
Updater: C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe 13.6.20.2100
Update resource: C:\Program Files (x86)\Avira\AntiVir Desktop\updaterc.dll 13.6.20.2174
Library: C:\Program Files (x86)\Avira\AntiVir Desktop\update.dll 1.0.0.9
GUI: C:\Program Files (x86)\Avira\AntiVir Desktop\updgui.dll 13.6.20.2174
Temp Directory: C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\
Backup folder: C:\ProgramData\Avira\AntiVir Desktop\BACKUP\
Installation Directory: C:\Program Files (x86)\Avira\AntiVir Desktop\
Updater folder: C:\Program Files (x86)\Avira\AntiVir Desktop\
AppData folder: C:\ProgramData\Avira\AntiVir Desktop\
Connection settings:
- Connection type: Web server
- Transfer type: Existing connection
Proxy settings: System settings used
22:47:22 [UPD] [INFO] Checking whether newer files are available.
22:47:22 [UPD] [INFO] Select update server 'hxxp://premium.avira-update.com/update'.
22:47:22 [UPD] [INFO] Downloading of 'hxxp://premium.avira-update.com/update/idx/master.idx' to 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
22:47:22 [UPDLIB] [ERROR] Download manager: Resolve host name failed while downloading the file hxxp://premium.avira-update.com/update/idx/master.idx
22:47:22 [UPDLIB] [ERROR] Retrying...
22:47:22 [UPD] [INFO] Downloading of 'hxxp://premium.avira-update.com/update/idx/master.idx' to 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
22:47:22 [UPDLIB] [ERROR] Download manager: Resolve host name failed while downloading the file hxxp://premium.avira-update.com/update/idx/master.idx
22:47:22 [UPDLIB] [ERROR] Retrying...
22:47:22 [UPD] [INFO] Downloading of 'hxxp://premium.avira-update.com/update/idx/master.idx' to 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
22:47:22 [UPDLIB] [ERROR] Download manager: Resolve host name failed while downloading the file hxxp://premium.avira-update.com/update/idx/master.idx
22:47:22 [UPD] [INFO] Select update server 'hxxp://premium.avira-update.net/update'.
22:47:22 [UPD] [INFO] Downloading of 'hxxp://premium.avira-update.net/update/idx/master.idx' to 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
22:47:22 [UPDLIB] [ERROR] Download manager: Resolve host name failed while downloading the file hxxp://premium.avira-update.net/update/idx/master.idx
22:47:22 [UPDLIB] [ERROR] Retrying...
22:47:22 [UPD] [INFO] Downloading of 'hxxp://premium.avira-update.net/update/idx/master.idx' to 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
22:47:22 [UPDLIB] [ERROR] Download manager: Resolve host name failed while downloading the file hxxp://premium.avira-update.net/update/idx/master.idx
22:47:22 [UPDLIB] [ERROR] Retrying...
22:47:22 [UPD] [INFO] Downloading of 'hxxp://premium.avira-update.net/update/idx/master.idx' to 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
22:47:22 [UPDLIB] [ERROR] Download manager: Resolve host name failed while downloading the file hxxp://premium.avira-update.net/update/idx/master.idx
22:47:22 [UPD] [INFO] Select update server 'hxxp://62.146.87.172/update'.
22:47:22 [UPD] [INFO] Downloading of 'hxxp://62.146.87.172/update/idx/master.idx' to 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
22:47:22 [UPDLIB] [ERROR] Download manager: Connection failed while downloading the file hxxp://62.146.87.172/update/idx/master.idx
22:47:22 [UPD] [INFO] Select update server 'hxxp://prempeak.avira-update.com/update'.
22:47:22 [UPD] [INFO] Downloading of 'hxxp://prempeak.avira-update.com/update/idx/master.idx' to 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
22:47:22 [UPDLIB] [ERROR] Download manager: Resolve host name failed while downloading the file hxxp://prempeak.avira-update.com/update/idx/master.idx
22:47:22 [UPDLIB] [ERROR] Retrying...
22:47:22 [UPD] [INFO] Downloading of 'hxxp://prempeak.avira-update.com/update/idx/master.idx' to 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
22:47:22 [UPDLIB] [ERROR] Download manager: Resolve host name failed while downloading the file hxxp://prempeak.avira-update.com/update/idx/master.idx
22:47:22 [UPDLIB] [ERROR] Retrying...
22:47:22 [UPD] [INFO] Downloading of 'hxxp://prempeak.avira-update.com/update/idx/master.idx' to 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
22:47:22 [UPDLIB] [ERROR] Download manager: Resolve host name failed while downloading the file hxxp://prempeak.avira-update.com/update/idx/master.idx
22:47:22 [UPDLIB] [ERROR] No other server, update aborted
22:47:22 [UPD] [ERROR] Generation of update structure failed. UpdateLib delivers error 537.
Summary:
********
0 Files downloaded
0 Files installed
Sonntag, 15. September 2013 22:47:22
The update failed! |