Konomono | 28.09.2013 18:16 | Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27-09-2013
Ran by Tobi at 2013-09-27 20:00:50
Running from C:\Users\Tobi\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Anti-Virus (Enabled - Up to date) {15414183-282E-D62C-CA37-EF24860A2F17}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Anti-Virus (Enabled - Up to date) {AE20A067-0E14-D9A2-F087-D456FD8D65AA}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168)
Adobe Reader X (10.1.8) - Deutsch (x32 Version: 10.1.8)
Alcor Micro USB Card Reader (x32 Version: 3.9.142.62248)
Apple Application Support (x32 Version: 2.3.6)
Apple Mobile Device Support (Version: 7.0.0.117)
Apple Software Update (x32 Version: 2.1.3.127)
ASUS Instant Connect (x32 Version: 1.2.8)
ASUS Instant Key (x32 Version: 1.0.5)
ASUS InstantOn (x32 Version: 3.0.5)
ASUS LifeFrame3 (x32 Version: 3.1.13)
ASUS Live Update (x32 Version: 3.1.9)
ASUS N Series Demo (x32 Version: 1.0.0003)
ASUS Power4Gear Hybrid (Version: 2.1.7)
ASUS Screen Saver (Version: 1.0.1)
ASUS Smart Gesture (x32 Version: 1.1.3)
ASUS Splendid Video Enhancement Technology (x32 Version: 2.01.0002)
ASUS Tutor (x32 Version: 1.0.8)
ASUS USB Charger Plus (x32 Version: 2.1.5)
ASUS Video Magic (x32 Version: 6.0.4713)
ASUS WebStorage Sync Agent (x32 Version: 1.1.10.123)
ASUSDVD (x32 Version: 10.0.4126.52)
ATK Package (x32 Version: 1.0.0027)
Bonjour (Version: 3.0.0.10)
Classic Shell (Version: 3.6.8)
Computer Security 12.83.104.0 (release) (x32 Version: 12.83.104.0)
CyberLink MediaEspresso 6.5 (x32 Version: 6.5.3019_44673)
CyberLink PowerDirector (x32 Version: 8.0.5817a)
D3DX10 (x32 Version: 15.4.2368.0902)
Fotogalerie (x32 Version: 16.4.3505.0912)
Free YouTube to MP3 Converter version 3.12.12.827 (x32 Version: 3.12.12.827)
F-Secure (x32 Version: 1.83.311.0)
F-Secure CCF Reputation (x32 Version: 1.0.25.1877)
F-Secure CCF Scanning 1.23.124.8831 (release) (x32 Version: 1.23.124.8831)
F-Secure Network CCF 1.02.128 (x32 Version: 1.02.128)
Galerie de photos (x32 Version: 16.4.3505.0912)
GIMP 2.8.4 (Version: 2.8.4)
Intel PROSet Wireless
Intel(R) Management Engine Components (x32 Version: 8.1.0.1252)
Intel(R) Processor Graphics (x32 Version: 9.17.10.2884)
Intel(R) PROSet/Wireless for Bluetooth(R) + High Speed (Version: 15.5.5.0480)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 2.6.1211.0294)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (x32 Version: 2.0.0.37149)
Intel(R) WiDi (Version: 3.5.41.0)
Intel® PROSet/Wireless WiFi Software (Version: 15.05.7000.1709)
Intel® Trusted Connect Service Client (Version: 1.24.388.1)
iTunes (Version: 11.1.0.126)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
McAfee Internet Security (x32 Version: 11.6.385)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office (x32 Version: 15.0.4420.1017)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Movie Maker (x32 Version: 16.4.3505.0912)
Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0)
Mozilla Maintenance Service (x32 Version: 24.0)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT110 (x32 Version: 16.4.1108.0727)
MSVCRT110_amd64 (Version: 16.4.1109.0912)
MyBitCast 2.0 (x32 Version: 2.0)
NVIDIA Control Panel 311.00 (Version: 311.00)
NVIDIA Graphics Driver 311.00 (Version: 311.00)
NVIDIA HD Audio Driver 1.3.18.0 (Version: 1.3.18.0)
NVIDIA Install Application (Version: 2.1002.108.688)
NVIDIA Optimus 1.11.3 (Version: 1.11.3)
NVIDIA PhysX (x32 Version: 9.12.1031)
NVIDIA PhysX System Software 9.12.1031 (Version: 9.12.1031)
NVIDIA Update 1.11.3 (Version: 1.11.3)
NVIDIA Update Components (Version: 1.11.3)
OpenOffice 4.0.0 (x32 Version: 4.00.9702)
Photo Common (x32 Version: 16.4.3505.0912)
Photo Gallery (x32 Version: 16.4.3505.0912)
Qualcomm Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 2.1.0.12)
Raccolta foto (x32 Version: 16.4.3505.0912)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6828)
Secunia PSI (3.0.0.7011) (x32 Version: 3.0.0.7011)
Shared C Run-time for x64 (Version: 10.0.0)
Skype™ 6.7 (x32 Version: 6.7.102)
Spotify (HKCU Version: 0.9.4.169.gc0399df6)
TmNationsForever (x32)
Windows Driver Package - ASUS (ATP) Mouse (01/10/2013 1.0.0.170) (Version: 01/10/2013 1.0.0.170)
Windows Live (x32 Version: 16.4.3505.0912)
Windows Live Communications Platform (x32 Version: 16.4.3505.0912)
Windows Live Essentials (x32 Version: 16.4.3505.0912)
Windows Live Installer (x32 Version: 16.4.3505.0912)
Windows Live Photo Common (x32 Version: 16.4.3505.0912)
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912)
Windows Live SOXE (x32 Version: 16.4.3505.0912)
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912)
Windows Live UX Platform (x32 Version: 16.4.3505.0912)
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912)
WinFlash (x32 Version: 2.41.1)
Xiph.Org Open Codecs 0.85.17777 (x32 Version: 0.85.17777)
==================== Restore Points =========================
Could not list Restore Points.
==================== Hosts content: ==========================
2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => ?
Task: C:\Windows\Tasks\Scheduled scanning task.job => ?
==================== Loaded Modules (whitelisted) =============
2013-01-28 12:44 - 2012-11-21 10:58 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/27/2013 07:19:59 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1485
Error: (09/27/2013 07:19:59 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1485
Error: (09/27/2013 06:13:23 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/27/2013 04:25:45 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1250
Error: (09/27/2013 04:25:45 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1250
Error: (09/27/2013 04:25:45 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/27/2013 04:01:22 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2577250
Error: (09/27/2013 04:01:22 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2577250
Error: (09/27/2013 04:01:22 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/26/2013 08:09:33 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 14969
System errors:
=============
Error: (09/27/2013 05:30:19 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Apple Mobile Device" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 60000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (09/26/2013 01:39:22 PM) (Source: Microsoft-Windows-Kernel-General) (User: NT-AUTORITÄT)
Description: 0x8000002a171\??\Volume{6271fb00-b661-4146-9b61-09fab44b02f9}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{6542C2C8-0FD7-4E3E-985C-2AA63876670A}
Error: (09/26/2013 01:39:14 PM) (Source: Microsoft-Windows-Kernel-General) (User: NT-AUTORITÄT)
Description: 0x8000002a78\??\GLOBALROOT\Device\HarddiskVolumeShadowCopy6\Windows\system32\config\SYSTEM
Error: (09/19/2013 11:12:33 AM) (Source: DCOM) (User: Tobis-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (09/19/2013 11:12:33 AM) (Source: DCOM) (User: Tobis-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (09/19/2013 11:12:33 AM) (Source: DCOM) (User: Tobis-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (09/19/2013 11:12:33 AM) (Source: DCOM) (User: Tobis-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (09/19/2013 11:12:30 AM) (Source: DCOM) (User: Tobis-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (09/19/2013 11:12:30 AM) (Source: DCOM) (User: Tobis-PC)
Description: {4545DEA0-2DFC-4906-A728-6D986BA399A9}
Error: (09/19/2013 11:12:29 AM) (Source: DCOM) (User: Tobis-PC)
Description: {078AEF33-C48A-49F7-AFF3-A0EE810BFE7C}
Microsoft Office Sessions:
=========================
Error: (09/27/2013 07:19:59 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1485
Error: (09/27/2013 07:19:59 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1485
Error: (09/27/2013 06:13:23 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/27/2013 04:25:45 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1250
Error: (09/27/2013 04:25:45 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1250
Error: (09/27/2013 04:25:45 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/27/2013 04:01:22 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2577250
Error: (09/27/2013 04:01:22 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2577250
Error: (09/27/2013 04:01:22 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/26/2013 08:09:33 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 14969
==================== Memory info ===========================
Percentage of memory in use: 52%
Total physical RAM: 3981.81 MB
Available physical RAM: 1873.64 MB
Total Pagefile: 4685.81 MB
Available Pagefile: 2207.57 MB
Total Virtual: 8192 MB
Available Virtual: 8191.77 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:186.3 GB) (Free:121.78 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATA) (Fixed) (Total:258.15 GB) (Free:256.65 GB) NTFS
==================== MBR & Partition Table ==================
==================== End Of Log ============================ Gmer: Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2013-09-27 20:08:51
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000003c ST500LT012-9WS142 rev.0001SDM1 465,76GB
Running: tjrbk90r.exe; Driver: C:\Users\Admin\AppData\Local\Temp\fgloipod.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000093200 7 bytes [40, 3B, 82, 01, 00, 53, F2]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff96000093208 7 bytes [01, 63, C0, FF, 00, 17, DB]
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\svchost.exe[808] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73b018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 2 bytes JMP 000007fbdd739018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\KERNELBASE.dll!CreateMutexW + 3 000007fb5a9e3413 2 bytes [D5, 82]
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbda9f0018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73a018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdd73f018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa22018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa21018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdd73d018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdd73c018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa20018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa50018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdd73e018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd736018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd734018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd737018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd733018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd735018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd738018
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\svchost.exe[808] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73d018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73b018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa72018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73c018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa71018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa76018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa75018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdd73f018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdd73e018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa73018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa74018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\USER32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\USER32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\nvvsvc.exe[848] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\svchost.exe[876] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73d018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73b018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa72018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73c018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa71018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa76018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa75018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdd73f018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdd73e018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa73018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa74018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd736018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd734018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd737018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd733018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd735018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd738018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd739018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73a018
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\svchost.exe[876] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73f018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73d018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa13018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73e018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa12018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa15018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa14018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdaa11018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdaa10018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa71018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa72018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd73b018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73c018
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Windows\System32\svchost.exe[936] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\svchost.exe[960] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73f018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73d018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa13018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73e018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa12018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa15018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa14018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdaa11018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdaa10018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa71018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa72018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd73b018
.text C:\Windows\system32\svchost.exe[960] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73c018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73f018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73d018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa13018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73e018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa12018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa15018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa14018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdaa11018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdaa10018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa71018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa72018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd73b018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73c018
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\svchost.exe[128] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Windows\System32\svchost.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73f018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73d018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa13018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73e018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa12018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa15018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa14018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdaa11018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdaa10018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa71018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa72018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd73b018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73c018
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Windows\System32\svchost.exe[536] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73f018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73d018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa13018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73e018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa12018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa15018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa14018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdaa11018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdaa10018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa71018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa72018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd73b018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73c018
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\svchost.exe[1216] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73f018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73d018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa13018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73e018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa12018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa15018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa14018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdaa11018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdaa10018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa71018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa72018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\USER32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\USER32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd73b018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73c018
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\MSIMG32.dll!GradientFill + 690 000007fb54701532 4 bytes [70, 54, FB, 07]
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\MSIMG32.dll!GradientFill + 698 000007fb5470153a 4 bytes [70, 54, FB, 07]
.text C:\Windows\system32\WLANExt.exe[1304] C:\Windows\system32\MSIMG32.dll!TransparentBlt + 246 000007fb5470165a 4 bytes [70, 54, FB, 07]
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73f018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73d018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa13018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73e018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa12018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa15018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa14018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdaa11018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdaa10018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa71018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa72018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd73b018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73c018
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\svchost.exe[1552] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73f018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73d018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa13018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73e018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa12018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa15018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa14018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdaa11018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdaa10018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa71018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa72018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd73b018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73c018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\USER32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\USER32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Program Files\Bonjour\mDNSResponder.exe[1768] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73f018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73d018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa13018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73e018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa12018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa15018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa14018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdaa11018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdaa10018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa71018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa72018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\USER32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\USER32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb54701532 4 bytes [70, 54, FB, 07]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb5470153a 4 bytes [70, 54, FB, 07]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb5470165a 4 bytes [70, 54, FB, 07]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd73b018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73c018
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1820] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73d018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73b018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa72018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73c018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa71018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa76018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa75018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdd73f018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdd73e018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa73018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa74018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\USER32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\USER32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Program Files\Intel\iCLS Client\HeciServer.exe[796] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73d018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73b018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa72018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73c018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa71018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa76018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa75018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdd73f018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdd73e018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa73018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa74018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\USER32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\system32\USER32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb54701532 4 bytes [70, 54, FB, 07]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb5470153a 4 bytes [70, 54, FB, 07]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2184] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb5470165a 4 bytes [70, 54, FB, 07]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73f018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73d018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa13018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73e018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa12018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa15018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa14018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdaa11018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdaa10018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa71018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa72018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\USER32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\USER32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd73b018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73c018
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb54701532 4 bytes [70, 54, FB, 07]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb5470153a 4 bytes [70, 54, FB, 07]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb5470165a 4 bytes [70, 54, FB, 07]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2412] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73f018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73d018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa13018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73e018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa12018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa15018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa14018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdaa11018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdaa10018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa71018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa72018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd73b018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73c018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\wbem\unsecapp.exe[3048] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73d018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73b018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa72018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73c018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa71018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa76018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa75018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdd73f018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdd73e018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa73018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa74018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd736018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd734018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd737018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd733018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd735018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd738018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd739018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73a018
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\svchost.exe[3200] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\wbem\wmiprvse.exe[3320] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\wbem\wmiprvse.exe[3320] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\wbem\wmiprvse.exe[3320] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007fb54701532 4 bytes [70, 54, FB, 07]
.text C:\Windows\system32\wbem\wmiprvse.exe[3320] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007fb5470153a 4 bytes [70, 54, FB, 07]
.text C:\Windows\system32\wbem\wmiprvse.exe[3320] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007fb5470165a 4 bytes [70, 54, FB, 07]
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73d018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73b018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa72018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73c018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa71018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa76018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa75018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdd73f018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdd73e018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa73018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa74018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\USER32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\USER32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe[1712] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73f018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73d018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa13018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73e018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa12018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa15018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa14018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdaa11018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdaa10018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa71018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa72018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd73b018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73c018
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Windows\system32\svchost.exe[3828] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73f018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73d018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa13018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\KERNELBASE.dll!CreateMutexExW 000007fb5a9ec3e4 5 bytes JMP 000007fbdd73e018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryW 000007fb5a9f2854 5 bytes JMP 000007fbdaa12018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\KERNELBASE.dll!TerminateThread 000007fb5a9fed8c 5 bytes JMP 000007fbdaa15018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThreadEx 000007fb5aa00af0 5 bytes JMP 000007fbdaa14018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\KERNELBASE.dll!CopyFileExW 000007fb5aa09770 5 bytes JMP 000007fbdaa11018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\KERNELBASE.dll!OpenMutexW 000007fb5aa0b6dc 5 bytes JMP 000007fbdaa10018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\KERNELBASE.dll!GetFileSizeEx 000007fb5aa17fa4 5 bytes JMP 000007fbdaa71018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory 000007fb5aa45c00 5 bytes JMP 000007fbdaa72018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\KERNELBASE.dll!CreateDirectoryExW 000007fb5aa669a0 5 bytes JMP 000007fbdaa70018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\USER32.dll!SetWindowsHookExW 000007fb5d16bee0 5 bytes JMP 000007fbdd734018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\USER32.dll!SetWindowsHookExA 000007fb5d191850 5 bytes JMP 000007fbdd733018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle 000007fb5d533ad0 5 bytes JMP 000007fbdd738018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 000007fb5d5341a0 5 bytes JMP 000007fbdd736018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\SYSTEM32\sechost.dll!CreateServiceW 000007fb5d5375d0 5 bytes JMP 000007fbdd739018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 000007fb5d537880 5 bytes JMP 000007fbdd735018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\SYSTEM32\sechost.dll!ControlService 000007fb5d538030 5 bytes JMP 000007fbdd737018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\SYSTEM32\sechost.dll!CreateServiceA 000007fb5d55b034 5 bytes JMP 000007fbdd73a018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\WS2_32.dll!recv 000007fb5b291f40 5 bytes JMP 000007fbdd73b018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\WS2_32.dll!send 000007fb5b293050 5 bytes JMP 000007fbdd73c018
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007fb5d15177a 4 bytes [15, 5D, FB, 07]
.text C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe[3992] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007fb5d151782 4 bytes [15, 5D, FB, 07]
.text C:\Windows\System32\WinLogon.exe[11596] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcessEx 000007fb5d7230b0 5 bytes JMP 000007fbdd731018
.text C:\Windows\System32\WinLogon.exe[11596] C:\Windows\SYSTEM32\ntdll.dll!NtCreateProcess 000007fb5d723691 5 bytes JMP 000007fbdd730018
.text C:\Windows\System32\WinLogon.exe[11596] C:\Windows\SYSTEM32\ntdll.dll!NtCreateUserProcess 000007fb5d723751 5 bytes JMP 000007fbdd732018
.text C:\Windows\System32\WinLogon.exe[11596] C:\Windows\system32\KERNEL32.DLL!OpenMutexA 000007fb5caefd28 5 bytes JMP 000007fbdd73d018
.text C:\Windows\System32\WinLogon.exe[11596] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 000007fb5a9e3410 5 bytes JMP 000007fbdd73b018
.text C:\Windows\System32\WinLogon.exe[11596] C:\Windows\system32\KERNELBASE.dll!GetFileSize 000007fb5a9e6370 5 bytes JMP 000007fbdaa72018
.text
|