GegenPegi | 19.03.2015 11:57 | Gmer: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-03-19 00:41:46
Windows 6.2.9200 x64 \Device\Harddisk1\DR1 -> \Device\00000038 Crucial_CT256MX100SSD1 rev.MU01 238,47GB
Running: Gmer-19357.exe; Driver: C:\Users\Matze\AppData\Local\Temp\uwliypow.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000104200 15 bytes [00, 28, F6, 01, 80, 1C, 6C, ...]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 16 fffff96000104210 11 bytes [00, 0E, FC, FF, 00, 05, C4, ...]
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe[984] C:\Windows\system32\KERNEL32.DLL!UnhandledExceptionFilter + 1 00007ff886060cf1 5 bytes [B8, 30, 08, 54, 01]
.text C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe[984] C:\Windows\system32\KERNEL32.DLL!UnhandledExceptionFilter + 7 00007ff886060cf7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!CloseHandle 00007ff8850e14c0 12 bytes [48, B8, 49, 4D, C4, 76, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!FreeLibrary + 1 00007ff8850e21d1 11 bytes [B8, 09, A3, C4, 76, 00, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!GetProcAddress 00007ff8850e42a0 12 bytes [48, B8, C9, A4, C4, 76, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 00007ff8850e6ed0 12 bytes [48, B8, 89, 4B, C4, 76, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!OpenMutexW + 1 00007ff8850e8a71 11 bytes [B8, C9, 49, C4, 76, 00, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 1 00007ff8850e8d81 11 bytes [B8, 49, A1, C4, 76, 00, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 00007ff8850e97b1 11 bytes [B8, 89, 9F, C4, 76, 00, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!MoveFileWithProgressW + 1 00007ff8850f2511 11 bytes [B8, C9, C7, C4, 76, 00, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8850fef70 12 bytes [48, B8, 89, 28, C4, 76, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory + 1 00007ff885116b21 11 bytes [B8, 89, 3D, C4, 76, 00, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!MoveFileExW + 1 00007ff8851393c1 8 bytes [B8, 89, C2, C4, 76, 00, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!MoveFileExW + 10 00007ff8851393ca 2 bytes [50, C3]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!DefineDosDeviceW + 1 00007ff88515a841 11 bytes [B8, 49, BD, C4, 76, 00, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!CreateThread 00007ff88515ac50 12 bytes [48, B8, C9, 3B, C4, 76, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!ReadConsoleInputA + 1 00007ff8851af811 11 bytes [B8, 49, 70, C4, 76, 00, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!ReadConsoleInputW + 1 00007ff8851af891 11 bytes [B8, 09, 72, C4, 76, 00, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!ReadConsoleA 00007ff8851b0340 12 bytes [48, B8, C9, 73, C4, 76, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!ReadConsoleW 00007ff8851b0570 12 bytes [48, B8, 89, 75, C4, 76, 00, ...]
.text C:\Windows\system32\dashost.exe[2232] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread 00007ff8851c0c80 12 bytes [48, B8, C9, 1F, C4, 76, 00, ...]
.text C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe[2768] C:\Windows\system32\KERNEL32.DLL!UnhandledExceptionFilter + 1 00007ff886060cf1 5 bytes [B8, 30, 08, 14, 01]
.text C:\Program Files\Bitdefender\Bitdefender 2015\updatesrv.exe[2768] C:\Windows\system32\KERNEL32.DLL!UnhandledExceptionFilter + 7 00007ff886060cf7 5 bytes [00, 00, 00, 50, C3]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNEL32.DLL!CreateToolhelp32Snapshot 00007ff885f9db10 12 bytes [48, B8, C9, 34, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNEL32.DLL!Process32NextW 00007ff885f9e1f0 12 bytes [48, B8, 49, AF, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNEL32.DLL!GetStartupInfoA + 1 00007ff8860334b1 11 bytes [B8, 09, D4, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNEL32.DLL!MoveFileExA + 1 00007ff88605aba1 8 bytes [B8, C9, C0, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNEL32.DLL!MoveFileExA + 10 00007ff88605abaa 2 bytes [50, C3]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNEL32.DLL!MoveFileWithProgressA + 1 00007ff88605aca1 11 bytes [B8, 09, C6, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!CloseHandle 00007ff8850e14c0 12 bytes [48, B8, 49, 4D, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!FreeLibrary + 1 00007ff8850e21d1 11 bytes [B8, 09, A3, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!GetProcAddress 00007ff8850e42a0 12 bytes [48, B8, C9, A4, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 00007ff8850e6ed0 12 bytes [48, B8, 89, 4B, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!OpenMutexW + 1 00007ff8850e8a71 11 bytes [B8, C9, 49, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 1 00007ff8850e8d81 11 bytes [B8, 49, A1, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 00007ff8850e97b1 11 bytes [B8, 89, 9F, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!MoveFileWithProgressW + 1 00007ff8850f2511 11 bytes [B8, C9, C7, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8850fef70 12 bytes [48, B8, 89, 28, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory + 1 00007ff885116b21 11 bytes [B8, 89, 3D, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!MoveFileExW + 1 00007ff8851393c1 8 bytes [B8, 89, C2, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!MoveFileExW + 10 00007ff8851393ca 2 bytes [50, C3]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!DefineDosDeviceW + 1 00007ff88515a841 11 bytes [B8, 49, BD, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!CreateThread 00007ff88515ac50 12 bytes [48, B8, C9, 3B, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!ReadConsoleInputA + 1 00007ff8851af811 11 bytes [B8, 49, 70, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!ReadConsoleInputW + 1 00007ff8851af891 11 bytes [B8, 09, 72, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!ReadConsoleA 00007ff8851b0340 12 bytes [48, B8, C9, 73, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!ReadConsoleW 00007ff8851b0570 12 bytes [48, B8, 89, 75, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread 00007ff8851c0c80 12 bytes [48, B8, C9, 1F, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\WS2_32.dll!closesocket 00007ff8857a1be0 12 bytes [48, B8, 89, 98, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\WS2_32.dll!recv + 1 00007ff8857a2571 11 bytes [B8, C9, CE, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\WS2_32.dll!WSASend + 1 00007ff8857a2d61 11 bytes [B8, 49, 9A, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\WS2_32.dll!WSARecv + 1 00007ff8857a2ff1 11 bytes [B8, 89, D0, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\WS2_32.dll!WSASocketW 00007ff8857a3880 12 bytes [48, B8, C9, 96, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\WS2_32.dll!socket + 1 00007ff8857a3bd1 11 bytes [B8, 89, C9, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\WS2_32.dll!GetAddrInfoW 00007ff8857a4230 12 bytes [48, B8, 09, 80, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\WS2_32.dll!connect 00007ff8857a5730 12 bytes [48, B8, 49, 62, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\WS2_32.dll!GetAddrInfoExW 00007ff8857a87e0 12 bytes [48, B8, C9, 81, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\WS2_32.dll!send + 1 00007ff8857b42d1 11 bytes [B8, 09, 95, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\WS2_32.dll!WSAConnect + 1 00007ff8857b6fe1 11 bytes [B8, 09, CD, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\system32\WS2_32.dll!gethostbyname + 1 00007ff8857c54b1 11 bytes [B8, 89, 83, C4, 76, 00, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\SYSTEM32\advapi32.dll!CreateServiceA 00007ff887b3dd10 12 bytes [48, B8, C9, 65, C4, 76, 00, ...]
.text C:\Windows\system32\wbem\wmiprvse.exe[5632] C:\Windows\SYSTEM32\advapi32.dll!CreateServiceW 00007ff887b3dda0 12 bytes [48, B8, 89, 67, C4, 76, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNEL32.DLL!CreateToolhelp32Snapshot 00007ff885f9db10 12 bytes [48, B8, C9, 34, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNEL32.DLL!Process32NextW 00007ff885f9e1f0 12 bytes [48, B8, 49, AF, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNEL32.DLL!GetStartupInfoA + 1 00007ff8860334b1 11 bytes [B8, 09, D4, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNEL32.DLL!MoveFileExA + 1 00007ff88605aba1 8 bytes [B8, C9, C0, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNEL32.DLL!MoveFileExA + 10 00007ff88605abaa 2 bytes [50, C3]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNEL32.DLL!MoveFileWithProgressA + 1 00007ff88605aca1 11 bytes [B8, 09, C6, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!CloseHandle 00007ff8850e14c0 12 bytes [48, B8, 49, 4D, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!FreeLibrary + 1 00007ff8850e21d1 11 bytes [B8, 09, A3, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!GetProcAddress 00007ff8850e42a0 12 bytes [48, B8, C9, A4, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 00007ff8850e6ed0 12 bytes [48, B8, 89, 4B, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!OpenMutexW + 1 00007ff8850e8a71 11 bytes [B8, C9, 49, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 1 00007ff8850e8d81 11 bytes [B8, 49, A1, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 00007ff8850e97b1 11 bytes [B8, 89, 9F, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!MoveFileWithProgressW + 1 00007ff8850f2511 11 bytes [B8, C9, C7, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8850fef70 12 bytes [48, B8, 89, 28, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory + 1 00007ff885116b21 11 bytes [B8, 89, 3D, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!MoveFileExW + 1 00007ff8851393c1 8 bytes [B8, 89, C2, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!MoveFileExW + 10 00007ff8851393ca 2 bytes [50, C3]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!DefineDosDeviceW + 1 00007ff88515a841 11 bytes [B8, 49, BD, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!CreateThread 00007ff88515ac50 12 bytes [48, B8, C9, 3B, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!ReadConsoleInputA + 1 00007ff8851af811 11 bytes [B8, 49, 70, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!ReadConsoleInputW + 1 00007ff8851af891 11 bytes [B8, 09, 72, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!ReadConsoleA 00007ff8851b0340 12 bytes [48, B8, C9, 73, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!ReadConsoleW 00007ff8851b0570 12 bytes [48, B8, 89, 75, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread 00007ff8851c0c80 12 bytes [48, B8, C9, 1F, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 00007ff885364981 11 bytes [B8, 09, 5D, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 00007ff885364f00 12 bytes [48, B8, C9, 50, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 00007ff885366921 11 bytes [B8, 49, 54, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\sechost.dll!ControlService + 1 00007ff885368c81 11 bytes [B8, 09, 56, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 00007ff88536bf70 12 bytes [48, B8, 09, 4F, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW + 1 00007ff885388b41 11 bytes [B8, 49, 5B, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\sechost.dll!DeleteService + 1 00007ff88538a0f1 11 bytes [B8, C9, 57, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA + 1 00007ff88538dc71 11 bytes [B8, 89, 59, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 00007ff88539dfd1 11 bytes [B8, 89, 52, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!ShowWindow 00007ff885cd11b0 6 bytes [48, B8, C9, 88, 09, 75]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!ShowWindow + 8 00007ff885cd11b8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!UnhookWindowsHookEx 00007ff885cd1210 6 bytes [48, B8, 89, 7C, 09, 75]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!UnhookWindowsHookEx + 8 00007ff885cd1218 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!GetMessageW 00007ff885cd2670 12 bytes [48, B8, 09, 6B, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!PeekMessageW + 1 00007ff885cd2991 11 bytes [B8, 89, 6E, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!CallNextHookEx 00007ff885cd2ef0 12 bytes [48, B8, C9, 7A, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!PostMessageW + 1 00007ff885cd33f1 11 bytes [B8, 49, D9, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!GetMessageA + 1 00007ff885cd6191 11 bytes [B8, 49, 69, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExW + 1 00007ff885cd6391 7 bytes [B8, 09, 1E, 09, 75, 00, 00]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExW + 9 00007ff885cd6399 3 bytes [00, 50, C3]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!CreateWindowExW 00007ff885cd6d90 7 bytes [48, B8, 49, 85, 09, 75, 00]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!CreateWindowExW + 10 00007ff885cd6d9a 2 bytes [50, C3]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!CreateWindowExA 00007ff885cdab30 7 bytes [48, B8, 09, 87, 09, 75, 00]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!CreateWindowExA + 10 00007ff885cdab3a 2 bytes [50, C3]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!SetWindowTextW + 1 00007ff885cdce31 11 bytes [B8, 49, 93, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!PeekMessageA + 1 00007ff885cddb41 11 bytes [B8, C9, 6C, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!UserClientDllInitialize + 1 00007ff885cddec1 11 bytes [B8, 09, E9, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!FindWindowW + 1 00007ff885ce0e61 7 bytes [B8, 09, AA, 09, 75, 00, 00]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!FindWindowW + 9 00007ff885ce0e69 3 bytes [00, 50, C3]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!SetWinEventHook 00007ff885ce7100 12 bytes [48, B8, 09, 3A, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!CreateDialogIndirectParamAorW + 1 00007ff885cf3ab1 11 bytes [B8, 89, 8A, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!PostMessageA + 1 00007ff885cf5921 11 bytes [B8, 89, D7, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!FindWindowExW + 1 00007ff885cf7161 11 bytes [B8, C9, AB, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!FindWindowExA + 1 00007ff885cf7691 5 bytes [B8, 49, A8, 09, 75]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!FindWindowExA + 9 00007ff885cf7699 3 bytes [00, 50, C3]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!DialogBoxIndirectParamAorW + 1 00007ff885d077a1 11 bytes [B8, 49, 8C, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExA + 1 00007ff885d30f61 8 bytes [B8, 49, 1C, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!SetWindowsHookExA + 10 00007ff885d30f6a 2 bytes [50, C3]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!MessageBoxExA + 1 00007ff885d57d01 11 bytes [B8, 09, 8E, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!MessageBoxExW + 1 00007ff885d57d31 11 bytes [B8, C9, 8F, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!SetWindowTextA + 1 00007ff885d61021 11 bytes [B8, 89, 91, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\SYSTEM32\user32.dll!FindWindowA + 1 00007ff885d61471 11 bytes [B8, 89, A6, 09, 75, 00, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\ADVAPI32.dll!CreateServiceA 00007ff887b3dd10 12 bytes [48, B8, C9, 65, 09, 75, 00, ...]
.text C:\Windows\system32\taskhostex.exe[5392] C:\Windows\system32\ADVAPI32.dll!CreateServiceW 00007ff887b3dda0 12 bytes [48, B8, 89, 67, 09, 75, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\KERNEL32.DLL!CreateToolhelp32Snapshot 00007ff885f9db10 12 bytes [48, B8, C9, 34, 09, 75, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\KERNEL32.DLL!GetStartupInfoA + 1 00007ff8860334b1 11 bytes [B8, 09, 6B, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\KERNEL32.DLL!MoveFileExA + 1 00007ff88605aba1 8 bytes [B8, 89, 60, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\KERNEL32.DLL!MoveFileExA + 10 00007ff88605abaa 2 bytes [50, C3]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\KERNEL32.DLL!MoveFileWithProgressA + 1 00007ff88605aca1 11 bytes [B8, C9, 65, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\KERNELBASE.dll!MoveFileWithProgressW + 1 00007ff8850f2511 11 bytes [B8, 89, 67, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8850fef70 12 bytes [48, B8, 89, 28, 09, 75, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory + 1 00007ff885116b21 11 bytes [B8, 89, 3D, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\KERNELBASE.dll!MoveFileExW + 1 00007ff8851393c1 8 bytes [B8, 49, 62, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\KERNELBASE.dll!MoveFileExW + 10 00007ff8851393ca 2 bytes [50, C3]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\KERNELBASE.dll!DefineDosDeviceW + 1 00007ff88515a841 11 bytes [B8, 09, 5D, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\KERNELBASE.dll!CreateThread 00007ff88515ac50 12 bytes [48, B8, C9, 3B, 09, 75, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread 00007ff8851c0c80 12 bytes [48, B8, C9, 1F, 09, 75, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\SYSTEM32\advapi32.dll!CreateServiceA 00007ff887b3dd10 12 bytes [48, B8, 89, 52, 09, 75, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\SYSTEM32\advapi32.dll!CreateServiceW 00007ff887b3dda0 12 bytes [48, B8, 49, 54, 09, 75, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\USER32.dll!GetMessageW 00007ff885cd2670 12 bytes [48, B8, 49, 70, 09, 75, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\USER32.dll!PostMessageW + 1 00007ff885cd33f1 11 bytes [B8, C9, 73, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\USER32.dll!GetMessageA + 1 00007ff885cd6191 11 bytes [B8, 89, 6E, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\USER32.dll!SetWindowsHookExW + 1 00007ff885cd6391 7 bytes [B8, 09, 1E, 09, 75, 00, 00]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\USER32.dll!SetWindowsHookExW + 9 00007ff885cd6399 3 bytes [00, 50, C3]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\USER32.dll!UserClientDllInitialize + 1 00007ff885cddec1 11 bytes [B8, 09, 80, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\USER32.dll!SetWinEventHook 00007ff885ce7100 12 bytes [48, B8, 09, 3A, 09, 75, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\USER32.dll!PostMessageA + 1 00007ff885cf5921 11 bytes [B8, 09, 72, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\USER32.dll!SetWindowsHookExA + 1 00007ff885d30f61 8 bytes [B8, 49, 1C, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\USER32.dll!SetWindowsHookExA + 10 00007ff885d30f6a 2 bytes [50, C3]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 00007ff885364981 11 bytes [B8, 49, 4D, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 00007ff885364f00 12 bytes [48, B8, 09, 41, 09, 75, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 00007ff885366921 11 bytes [B8, 89, 44, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\SYSTEM32\sechost.dll!ControlService + 1 00007ff885368c81 11 bytes [B8, 49, 46, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 00007ff88536bf70 12 bytes [48, B8, 49, 3F, 09, 75, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW + 1 00007ff885388b41 11 bytes [B8, 89, 4B, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\SYSTEM32\sechost.dll!DeleteService + 1 00007ff88538a0f1 11 bytes [B8, 09, 48, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA + 1 00007ff88538dc71 11 bytes [B8, C9, 49, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 00007ff88539dfd1 11 bytes [B8, C9, 42, 09, 75, 00, 00, ...]
.text C:\Windows\Explorer.EXE[8484] C:\Windows\system32\WS2_32.dll!connect 00007ff8857a5730 12 bytes [48, B8, 09, 4F, 09, 75, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[6396] C:\Windows\system32\KERNEL32.DLL!CreateToolhelp32Snapshot 00007ff885f9db10 12 bytes [48, B8, C9, 34, 09, 75, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[6396] C:\Windows\system32\KERNEL32.DLL!Process32NextW 00007ff885f9e1f0 12 bytes [48, B8, 49, CB, 09, 75, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[6396] C:\Windows\system32\KERNEL32.DLL!GetStartupInfoA + 1 00007ff8860334b1 11 bytes [B8, 09, F0, 09, 75, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[6396] C:\Windows\system32\KERNEL32.DLL!MoveFileExA + 1 00007ff88605aba1 8 bytes [B8, C9, DC, 09, 75, 00, 00, ...]
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[6396] C:\Windows\system32\KERNEL32.DLL!MoveFileExA + 10 00007ff88605abaa 2 bytes [50, C3]
.text C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe[6396] C:\Windows\system32\KERNEL32.DLL!MoveFileWithProgressA + 1 00007ff88605aca1 11 bytes [B8, 09, E2, 09, 75, 00, 00, ...]
.text C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe[8420] C:\Windows\system32\KERNEL32.DLL!UnhandledExceptionFilter + 1 00007ff886060cf1 5 bytes [B8, 30, 08, 68, 00]
.text C:\Program Files\Bitdefender\Bitdefender 2015\bdwtxag.exe[8420] C:\Windows\system32\KERNEL32.DLL!UnhandledExceptionFilter + 7 00007ff886060cf7 5 bytes [00, 00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNEL32.DLL!CreateToolhelp32Snapshot 00007ff885f9db10 12 bytes [48, B8, C9, 34, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNEL32.DLL!Process32NextW 00007ff885f9e1f0 12 bytes [48, B8, 49, AF, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNEL32.DLL!GetStartupInfoA + 1 00007ff8860334b1 11 bytes [B8, 09, D4, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNEL32.DLL!MoveFileExA + 1 00007ff88605aba1 8 bytes [B8, C9, C0, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNEL32.DLL!MoveFileExA + 10 00007ff88605abaa 2 bytes [50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNEL32.DLL!MoveFileWithProgressA + 1 00007ff88605aca1 11 bytes [B8, 09, C6, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!CloseHandle 00007ff8850e14c0 12 bytes [48, B8, 49, 4D, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!FreeLibrary + 1 00007ff8850e21d1 11 bytes [B8, 09, A3, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!GetProcAddress 00007ff8850e42a0 12 bytes [48, B8, C9, A4, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 00007ff8850e6ed0 12 bytes [48, B8, 89, 4B, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!OpenMutexW + 1 00007ff8850e8a71 11 bytes [B8, C9, 49, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 1 00007ff8850e8d81 11 bytes [B8, 49, A1, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 00007ff8850e97b1 11 bytes [B8, 89, 9F, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!MoveFileWithProgressW + 1 00007ff8850f2511 11 bytes [B8, C9, C7, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8850fef70 12 bytes [48, B8, 89, 28, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory + 1 00007ff885116b21 11 bytes [B8, 89, 3D, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!MoveFileExW + 1 00007ff8851393c1 8 bytes [B8, 89, C2, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!MoveFileExW + 10 00007ff8851393ca 2 bytes [50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!DefineDosDeviceW + 1 00007ff88515a841 11 bytes [B8, 49, BD, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!CreateThread 00007ff88515ac50 12 bytes [48, B8, C9, 3B, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!ReadConsoleInputA + 1 00007ff8851af811 11 bytes [B8, 49, 70, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!ReadConsoleInputW + 1 00007ff8851af891 11 bytes [B8, 09, 72, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!ReadConsoleA 00007ff8851b0340 12 bytes [48, B8, C9, 73, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!ReadConsoleW 00007ff8851b0570 12 bytes [48, B8, 89, 75, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread 00007ff8851c0c80 12 bytes [48, B8, C9, 1F, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\ADVAPI32.dll!CreateServiceA 00007ff887b3dd10 12 bytes [48, B8, C9, 65, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\ADVAPI32.dll!CreateServiceW 00007ff887b3dda0 12 bytes [48, B8, 89, 67, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!ShowWindow 00007ff885cd11b0 6 bytes [48, B8, C9, 88, 09, 75]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!ShowWindow + 8 00007ff885cd11b8 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!UnhookWindowsHookEx 00007ff885cd1210 6 bytes [48, B8, 89, 7C, 09, 75]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!UnhookWindowsHookEx + 8 00007ff885cd1218 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!GetMessageW 00007ff885cd2670 12 bytes [48, B8, 09, 6B, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!PeekMessageW + 1 00007ff885cd2991 11 bytes [B8, 89, 6E, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!CallNextHookEx 00007ff885cd2ef0 12 bytes [48, B8, C9, 7A, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!PostMessageW + 1 00007ff885cd33f1 11 bytes [B8, 49, D9, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!GetMessageA + 1 00007ff885cd6191 11 bytes [B8, 49, 69, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!SetWindowsHookExW + 1 00007ff885cd6391 7 bytes [B8, 09, 1E, 09, 75, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!SetWindowsHookExW + 9 00007ff885cd6399 3 bytes [00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!CreateWindowExW 00007ff885cd6d90 7 bytes [48, B8, 49, 85, 09, 75, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!CreateWindowExW + 10 00007ff885cd6d9a 2 bytes [50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!CreateWindowExA 00007ff885cdab30 7 bytes [48, B8, 09, 87, 09, 75, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!CreateWindowExA + 10 00007ff885cdab3a 2 bytes [50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!SetWindowTextW + 1 00007ff885cdce31 11 bytes [B8, 49, 93, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!PeekMessageA + 1 00007ff885cddb41 11 bytes [B8, C9, 6C, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!UserClientDllInitialize + 1 00007ff885cddec1 11 bytes [B8, 09, E9, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!FindWindowW + 1 00007ff885ce0e61 7 bytes [B8, 09, AA, 09, 75, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!FindWindowW + 9 00007ff885ce0e69 3 bytes [00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!SetWinEventHook 00007ff885ce7100 12 bytes [48, B8, 09, 3A, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!CreateDialogIndirectParamAorW + 1 00007ff885cf3ab1 11 bytes [B8, 89, 8A, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!PostMessageA + 1 00007ff885cf5921 11 bytes [B8, 89, D7, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!FindWindowExW + 1 00007ff885cf7161 11 bytes [B8, C9, AB, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!FindWindowExA + 1 00007ff885cf7691 5 bytes [B8, 49, A8, 09, 75]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!FindWindowExA + 9 00007ff885cf7699 3 bytes [00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!DialogBoxIndirectParamAorW + 1 00007ff885d077a1 11 bytes [B8, 49, 8C, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!SetWindowsHookExA + 1 00007ff885d30f61 8 bytes [B8, 49, 1C, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!SetWindowsHookExA + 10 00007ff885d30f6a 2 bytes [50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!MessageBoxExA + 1 00007ff885d57d01 11 bytes [B8, 09, 8E, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!MessageBoxExW + 1 00007ff885d57d31 11 bytes [B8, C9, 8F, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!SetWindowTextA + 1 00007ff885d61021 11 bytes [B8, 89, 91, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\USER32.dll!FindWindowA + 1 00007ff885d61471 11 bytes [B8, 89, A6, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 00007ff885364981 11 bytes [B8, 09, 5D, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 00007ff885364f00 12 bytes [48, B8, C9, 50, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 00007ff885366921 11 bytes [B8, 49, 54, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\SYSTEM32\sechost.dll!ControlService + 1 00007ff885368c81 11 bytes [B8, 09, 56, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 00007ff88536bf70 12 bytes [48, B8, 09, 4F, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW + 1 00007ff885388b41 11 bytes [B8, 49, 5B, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\SYSTEM32\sechost.dll!DeleteService + 1 00007ff88538a0f1 11 bytes [B8, C9, 57, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA + 1 00007ff88538dc71 11 bytes [B8, 89, 59, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 00007ff88539dfd1 11 bytes [B8, 89, 52, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[8516] C:\Windows\system32\SHELL32.dll!Shell_NotifyIconW + 1 00007ff886320f61 11 bytes [B8, 49, 7E, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNEL32.DLL!CreateToolhelp32Snapshot 00007ff885f9db10 12 bytes [48, B8, C9, 34, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNEL32.DLL!Process32NextW 00007ff885f9e1f0 12 bytes [48, B8, 49, AF, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNEL32.DLL!GetStartupInfoA + 1 00007ff8860334b1 11 bytes [B8, 09, D4, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNEL32.DLL!MoveFileExA + 1 00007ff88605aba1 8 bytes [B8, C9, C0, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNEL32.DLL!MoveFileExA + 10 00007ff88605abaa 2 bytes [50, C3]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNEL32.DLL!MoveFileWithProgressA + 1 00007ff88605aca1 11 bytes [B8, 09, C6, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!CloseHandle 00007ff8850e14c0 12 bytes [48, B8, 49, 4D, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!FreeLibrary + 1 00007ff8850e21d1 11 bytes [B8, 09, A3, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!GetProcAddress 00007ff8850e42a0 12 bytes [48, B8, C9, A4, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 00007ff8850e6ed0 12 bytes [48, B8, 89, 4B, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!OpenMutexW + 1 00007ff8850e8a71 11 bytes [B8, C9, 49, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 1 00007ff8850e8d81 11 bytes [B8, 49, A1, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 00007ff8850e97b1 11 bytes [B8, 89, 9F, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!MoveFileWithProgressW + 1 00007ff8850f2511 11 bytes [B8, C9, C7, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8850fef70 12 bytes [48, B8, 89, 28, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory + 1 00007ff885116b21 11 bytes [B8, 89, 3D, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!MoveFileExW + 1 00007ff8851393c1 8 bytes [B8, 89, C2, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!MoveFileExW + 10 00007ff8851393ca 2 bytes [50, C3]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!DefineDosDeviceW + 1 00007ff88515a841 11 bytes [B8, 49, BD, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!CreateThread 00007ff88515ac50 12 bytes [48, B8, C9, 3B, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!ReadConsoleInputA + 1 00007ff8851af811 11 bytes [B8, 49, 70, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!ReadConsoleInputW + 1 00007ff8851af891 11 bytes [B8, 09, 72, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!ReadConsoleA 00007ff8851b0340 12 bytes [48, B8, C9, 73, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!ReadConsoleW 00007ff8851b0570 12 bytes [48, B8, 89, 75, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread 00007ff8851c0c80 12 bytes [48, B8, C9, 1F, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\ADVAPI32.dll!CreateServiceA 00007ff887b3dd10 12 bytes [48, B8, C9, 65, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\ADVAPI32.dll!CreateServiceW 00007ff887b3dda0 12 bytes [48, B8, 89, 67, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!ShowWindow 00007ff885cd11b0 6 bytes [48, B8, C9, 88, 09, 75]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!ShowWindow + 8 00007ff885cd11b8 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!UnhookWindowsHookEx 00007ff885cd1210 6 bytes [48, B8, 89, 7C, 09, 75]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!UnhookWindowsHookEx + 8 00007ff885cd1218 4 bytes [00, 00, 50, C3]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!GetMessageW 00007ff885cd2670 12 bytes [48, B8, 09, 6B, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!PeekMessageW + 1 00007ff885cd2991 11 bytes [B8, 89, 6E, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!CallNextHookEx 00007ff885cd2ef0 12 bytes [48, B8, C9, 7A, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!PostMessageW + 1 00007ff885cd33f1 11 bytes [B8, 49, D9, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!GetMessageA + 1 00007ff885cd6191 11 bytes [B8, 49, 69, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!SetWindowsHookExW + 1 00007ff885cd6391 7 bytes [B8, 09, 1E, 09, 75, 00, 00]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!SetWindowsHookExW + 9 00007ff885cd6399 3 bytes [00, 50, C3]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!CreateWindowExW 00007ff885cd6d90 7 bytes [48, B8, 49, 85, 09, 75, 00]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!CreateWindowExW + 10 00007ff885cd6d9a 2 bytes [50, C3]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!CreateWindowExA 00007ff885cdab30 7 bytes [48, B8, 09, 87, 09, 75, 00]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!CreateWindowExA + 10 00007ff885cdab3a 2 bytes [50, C3]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!SetWindowTextW + 1 00007ff885cdce31 11 bytes [B8, 49, 93, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!PeekMessageA + 1 00007ff885cddb41 11 bytes [B8, C9, 6C, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!UserClientDllInitialize + 1 00007ff885cddec1 11 bytes [B8, 09, E9, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!FindWindowW + 1 00007ff885ce0e61 7 bytes [B8, 09, AA, 09, 75, 00, 00]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!FindWindowW + 9 00007ff885ce0e69 3 bytes [00, 50, C3]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!SetWinEventHook 00007ff885ce7100 12 bytes [48, B8, 09, 3A, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!CreateDialogIndirectParamAorW + 1 00007ff885cf3ab1 11 bytes [B8, 89, 8A, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!PostMessageA + 1 00007ff885cf5921 11 bytes [B8, 89, D7, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!FindWindowExW + 1 00007ff885cf7161 11 bytes [B8, C9, AB, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!FindWindowExA + 1 00007ff885cf7691 5 bytes [B8, 49, A8, 09, 75]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!FindWindowExA + 9 00007ff885cf7699 3 bytes [00, 50, C3]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!DialogBoxIndirectParamAorW + 1 00007ff885d077a1 11 bytes [B8, 49, 8C, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!SetWindowsHookExA + 1 00007ff885d30f61 8 bytes [B8, 49, 1C, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!SetWindowsHookExA + 10 00007ff885d30f6a 2 bytes [50, C3]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!MessageBoxExA + 1 00007ff885d57d01 11 bytes [B8, 09, 8E, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!MessageBoxExW + 1 00007ff885d57d31 11 bytes [B8, C9, 8F, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!SetWindowTextA + 1 00007ff885d61021 11 bytes [B8, 89, 91, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\USER32.dll!FindWindowA + 1 00007ff885d61471 11 bytes [B8, 89, A6, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 00007ff885364981 11 bytes [B8, 09, 5D, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 00007ff885364f00 12 bytes [48, B8, C9, 50, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 00007ff885366921 11 bytes [B8, 49, 54, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\SYSTEM32\sechost.dll!ControlService + 1 00007ff885368c81 11 bytes [B8, 09, 56, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 00007ff88536bf70 12 bytes [48, B8, 09, 4F, 09, 75, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW + 1 00007ff885388b41 11 bytes [B8, 49, 5B, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\SYSTEM32\sechost.dll!DeleteService + 1 00007ff88538a0f1 11 bytes [B8, C9, 57, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA + 1 00007ff88538dc71 11 bytes [B8, 89, 59, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 00007ff88539dfd1 11 bytes [B8, 89, 52, 09, 75, 00, 00, ...]
.text C:\Windows\system32\nvvsvc.exe[7908] C:\Windows\system32\SHELL32.dll!Shell_NotifyIconW + 1 00007ff886320f61 11 bytes [B8, 49, 7E, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNEL32.DLL!CreateToolhelp32Snapshot 00007ff885f9db10 12 bytes [48, B8, C9, 34, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNEL32.DLL!Process32NextW 00007ff885f9e1f0 12 bytes [48, B8, 49, AF, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNEL32.DLL!GetStartupInfoA + 1 00007ff8860334b1 11 bytes [B8, 09, D4, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNEL32.DLL!MoveFileExA + 1 00007ff88605aba1 8 bytes [B8, C9, C0, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNEL32.DLL!MoveFileExA + 10 00007ff88605abaa 2 bytes [50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNEL32.DLL!MoveFileWithProgressA + 1 00007ff88605aca1 11 bytes [B8, 09, C6, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!CloseHandle 00007ff8850e14c0 12 bytes [48, B8, 49, 4D, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!FreeLibrary + 1 00007ff8850e21d1 11 bytes [B8, 09, A3, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!GetProcAddress 00007ff8850e42a0 12 bytes [48, B8, C9, A4, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!CreateMutexW 00007ff8850e6ed0 12 bytes [48, B8, 89, 4B, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!OpenMutexW + 1 00007ff8850e8a71 11 bytes [B8, C9, 49, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 1 00007ff8850e8d81 11 bytes [B8, 49, A1, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExA + 1 00007ff8850e97b1 11 bytes [B8, 89, 9F, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!MoveFileWithProgressW + 1 00007ff8850f2511 11 bytes [B8, C9, C7, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!CreateProcessInternalW 00007ff8850fef70 12 bytes [48, B8, 89, 28, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!WriteProcessMemory + 1 00007ff885116b21 11 bytes [B8, 89, 3D, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!MoveFileExW + 1 00007ff8851393c1 8 bytes [B8, 89, C2, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!MoveFileExW + 10 00007ff8851393ca 2 bytes [50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!DefineDosDeviceW + 1 00007ff88515a841 11 bytes [B8, 49, BD, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!CreateThread 00007ff88515ac50 12 bytes [48, B8, C9, 3B, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!ReadConsoleInputA + 1 00007ff8851af811 11 bytes [B8, 49, 70, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!ReadConsoleInputW + 1 00007ff8851af891 11 bytes [B8, 09, 72, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!ReadConsoleA 00007ff8851b0340 12 bytes [48, B8, C9, 73, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!ReadConsoleW 00007ff8851b0570 12 bytes [48, B8, 89, 75, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\KERNELBASE.dll!CreateRemoteThread 00007ff8851c0c80 12 bytes [48, B8, C9, 1F, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!ShowWindow 00007ff885cd11b0 6 bytes [48, B8, C9, 88, 09, 75]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!ShowWindow + 8 00007ff885cd11b8 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!UnhookWindowsHookEx 00007ff885cd1210 6 bytes [48, B8, 89, 7C, 09, 75]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!UnhookWindowsHookEx + 8 00007ff885cd1218 4 bytes [00, 00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!GetMessageW 00007ff885cd2670 12 bytes [48, B8, 09, 6B, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!PeekMessageW + 1 00007ff885cd2991 11 bytes [B8, 89, 6E, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!CallNextHookEx 00007ff885cd2ef0 12 bytes [48, B8, C9, 7A, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!PostMessageW + 1 00007ff885cd33f1 11 bytes [B8, 49, D9, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!GetMessageA + 1 00007ff885cd6191 11 bytes [B8, 49, 69, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!SetWindowsHookExW + 1 00007ff885cd6391 7 bytes [B8, 09, 1E, 09, 75, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!SetWindowsHookExW + 9 00007ff885cd6399 3 bytes [00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!CreateWindowExW 00007ff885cd6d90 7 bytes [48, B8, 49, 85, 09, 75, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!CreateWindowExW + 10 00007ff885cd6d9a 2 bytes [50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!CreateWindowExA 00007ff885cdab30 7 bytes [48, B8, 09, 87, 09, 75, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!CreateWindowExA + 10 00007ff885cdab3a 2 bytes [50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!SetWindowTextW + 1 00007ff885cdce31 11 bytes [B8, 49, 93, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!PeekMessageA + 1 00007ff885cddb41 11 bytes [B8, C9, 6C, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!UserClientDllInitialize + 1 00007ff885cddec1 11 bytes [B8, 49, E7, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!FindWindowW + 1 00007ff885ce0e61 7 bytes [B8, 09, AA, 09, 75, 00, 00]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!FindWindowW + 9 00007ff885ce0e69 3 bytes [00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!SetWinEventHook 00007ff885ce7100 12 bytes [48, B8, 09, 3A, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!CreateDialogIndirectParamAorW + 1 00007ff885cf3ab1 11 bytes [B8, 89, 8A, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!PostMessageA + 1 00007ff885cf5921 11 bytes [B8, 89, D7, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!FindWindowExW + 1 00007ff885cf7161 11 bytes [B8, C9, AB, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!FindWindowExA + 1 00007ff885cf7691 5 bytes [B8, 49, A8, 09, 75]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!FindWindowExA + 9 00007ff885cf7699 3 bytes [00, 50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!DialogBoxIndirectParamAorW + 1 00007ff885d077a1 11 bytes [B8, 49, 8C, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!SetWindowsHookExA + 1 00007ff885d30f61 8 bytes [B8, 49, 1C, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!SetWindowsHookExA + 10 00007ff885d30f6a 2 bytes [50, C3]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!MessageBoxExA + 1 00007ff885d57d01 11 bytes [B8, 09, 8E, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!MessageBoxExW + 1 00007ff885d57d31 11 bytes [B8, C9, 8F, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!SetWindowTextA + 1 00007ff885d61021 11 bytes [B8, 89, 91, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\USER32.dll!FindWindowA + 1 00007ff885d61471 11 bytes [B8, 89, A6, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\ADVAPI32.dll!CreateServiceA 00007ff887b3dd10 12 bytes [48, B8, C9, 65, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\ADVAPI32.dll!CreateServiceW 00007ff887b3dda0 12 bytes [48, B8, 89, 67, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\SHELL32.dll!Shell_NotifyIconW + 1 00007ff886320f61 11 bytes [B8, 49, 7E, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\SYSTEM32\sechost.dll!CloseServiceHandle + 1 00007ff885364981 11 bytes [B8, 09, 5D, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\SYSTEM32\sechost.dll!OpenServiceW 00007ff885364f00 12 bytes [48, B8, C9, 50, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExW + 1 00007ff885366921 11 bytes [B8, 49, 54, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\SYSTEM32\sechost.dll!ControlService + 1 00007ff885368c81 11 bytes [B8, 09, 56, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\SYSTEM32\sechost.dll!OpenServiceA 00007ff88536bf70 12 bytes [48, B8, 09, 4F, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigW + 1 00007ff885388b41 11 bytes [B8, 49, 5B, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\SYSTEM32\sechost.dll!DeleteService + 1 00007ff88538a0f1 11 bytes [B8, C9, 57, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\SYSTEM32\sechost.dll!ChangeServiceConfigA + 1 00007ff88538dc71 11 bytes [B8, 89, 59, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\SYSTEM32\sechost.dll!ControlServiceExA + 1 00007ff88539dfd1 11 bytes [B8, 89, 52, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\WS2_32.dll!closesocket 00007ff8857a1be0 12 bytes [48, B8, 89, 98, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\WS2_32.dll!recv + 1 00007ff8857a2571 11 bytes [B8, C9, CE, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\WS2_32.dll!WSASend + 1 00007ff8857a2d61 11 bytes [B8, 49, 9A, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\WS2_32.dll!WSARecv + 1 00007ff8857a2ff1 11 bytes [B8, 89, D0, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\WS2_32.dll!WSASocketW 00007ff8857a3880 12 bytes [48, B8, C9, 96, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\WS2_32.dll!socket + 1 00007ff8857a3bd1 11 bytes [B8, 89, C9, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\WS2_32.dll!GetAddrInfoW 00007ff8857a4230 12 bytes [48, B8, 09, 80, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\WS2_32.dll!connect 00007ff8857a5730 12 bytes [48, B8, 49, 62, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\WS2_32.dll!GetAddrInfoExW 00007ff8857a87e0 12 bytes [48, B8, C9, 81, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\WS2_32.dll!send + 1 00007ff8857b42d1 11 bytes [B8, 09, 95, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\WS2_32.dll!WSAConnect + 1 00007ff8857b6fe1 11 bytes [B8, 09, CD, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\system32\WS2_32.dll!gethostbyname + 1 00007ff8857c54b1 11 bytes [B8, 89, 83, 09, 75, 00, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\SYSTEM32\DNSAPI.dll!DnsQueryEx 00007ff884444420 12 bytes [48, B8, 89, BB, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\SYSTEM32\DNSAPI.dll!DnsQuery_UTF8 00007ff884463cd0 12 bytes [48, B8, C9, B9, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\SYSTEM32\DNSAPI.dll!DnsQuery_W 00007ff884464350 12 bytes [48, B8, 09, B8, 09, 75, 00, ...]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[4076] C:\Windows\SYSTEM32\DNSAPI.dll!DnsQuery_A 00007ff88449fd90 12 bytes [48, B8, 49, B6, 09, 75, 00, ...]
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [3084:3048] fffff960008de2d0
---- Processes - GMER 2.1 ----
Library \\?\C:\Program Files\Common Files\Bitdefender\Bitdefender Threat Scanner\trufos.dll (*** suspicious ***) @ C:\Program Files\Bitdefender\Bitdefender 2015\vsserv.exe [984] (FILE NOT FOUND) 00007ff87f070000
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk1\DR1 unknown MBR code
---- EOF - GMER 2.1 ----
Danke |