Code:
C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e5144a 2 bytes CALL 7785489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe[2460] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e514dd 2 bytes JMP 778f8822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe[2460] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e514f5 2 bytes JMP 778f89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe[2460] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e5150d 2 bytes JMP 778f8718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe[2460] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e51525 2 bytes JMP 778f8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe[2460] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e5153d 2 bytes JMP 7786fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe[2460] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e51555 2 bytes JMP 778768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe[2460] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e5156d 2 bytes JMP 778f8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe[2460] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e51585 2 bytes JMP 778f8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe[2460] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e5159d 2 bytes JMP 778f86dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe[2460] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e515b5 2 bytes JMP 7786fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe[2460] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e515cd 2 bytes JMP 7787b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe[2460] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e516b2 2 bytes JMP 778f8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\MOUSE Editor\MouseEditor.exe[2460] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e516bd 2 bytes JMP 778f8671 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075c578e2 6 bytes [68, E0, 40, 5B, 75, C3]
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075c57bd3 6 bytes [68, 40, 40, 5B, 75, C3]
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075c605ba 6 bytes [68, 30, 42, 5B, 75, C3]
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075c65f74 6 bytes [68, 80, 41, 5B, 75, C3]
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075c750ed 6 bytes [68, 40, 3F, 5B, 75, C3]
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075c7c701 6 bytes [68, C0, 3F, 5B, 75, C3]
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 4 00000000747813b0 2 bytes JMP 765a5660 C:\Windows\syswow64\SHELL32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathW + 20 00000000747813c0 2 bytes CALL 76329cee C:\Windows\syswow64\msvcrt.dll
.text ... * 20
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 22 000000007478153e 2 bytes CALL 76637794 C:\Windows\syswow64\SHELL32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\SysWOW64\SHFOLDER.dll!SHGetFolderPathA + 43 0000000074781553 2 bytes CALL 778510ff C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e51401 2 bytes JMP 7787b21b C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e51419 2 bytes JMP 7787b346 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e51431 2 bytes JMP 778f8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e5144a 2 bytes CALL 7785489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e514dd 2 bytes JMP 778f8822 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e514f5 2 bytes JMP 778f89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e5150d 2 bytes JMP 778f8718 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e51525 2 bytes JMP 778f8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e5153d 2 bytes JMP 7786fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e51555 2 bytes JMP 778768ef C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e5156d 2 bytes JMP 778f8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e51585 2 bytes JMP 778f8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e5159d 2 bytes JMP 778f86dc C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e515b5 2 bytes JMP 7786fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e515cd 2 bytes JMP 7787b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e516b2 2 bytes JMP 778f8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnat.exe[1052] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e516bd 2 bytes JMP 778f8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075c578e2 6 bytes [68, E0, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075c57bd3 6 bytes [68, 40, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075c605ba 6 bytes [68, 30, 42, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075c65f74 6 bytes [68, 80, 41, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075c750ed 6 bytes [68, 40, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075c7c701 6 bytes [68, C0, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e51401 2 bytes JMP 7787b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e51419 2 bytes JMP 7787b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e51431 2 bytes JMP 778f8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e5144a 2 bytes CALL 7785489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e514dd 2 bytes JMP 778f8822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e514f5 2 bytes JMP 778f89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e5150d 2 bytes JMP 778f8718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e51525 2 bytes JMP 778f8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e5153d 2 bytes JMP 7786fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e51555 2 bytes JMP 778768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e5156d 2 bytes JMP 778f8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e51585 2 bytes JMP 778f8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e5159d 2 bytes JMP 778f86dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e515b5 2 bytes JMP 7786fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e515cd 2 bytes JMP 7787b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e516b2 2 bytes JMP 778f8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe[3184] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e516bd 2 bytes JMP 778f8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e51401 2 bytes JMP 7787b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e51419 2 bytes JMP 7787b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e51431 2 bytes JMP 778f8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e5144a 2 bytes CALL 7785489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e514dd 2 bytes JMP 778f8822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e514f5 2 bytes JMP 778f89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e5150d 2 bytes JMP 778f8718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e51525 2 bytes JMP 778f8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e5153d 2 bytes JMP 7786fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e51555 2 bytes JMP 778768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e5156d 2 bytes JMP 778f8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e51585 2 bytes JMP 778f8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e5159d 2 bytes JMP 778f86dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e515b5 2 bytes JMP 7786fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e515cd 2 bytes JMP 7787b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e516b2 2 bytes JMP 778f8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe[3576] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e516bd 2 bytes JMP 778f8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\kernel32.dll!CreateThread + 28 00000000778534a1 4 bytes {CALL 0xffffffff89a845b0}
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075c578e2 6 bytes [68, E0, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075c57bd3 6 bytes [68, 40, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075c605ba 6 bytes [68, 30, 42, 5B, 75, C3]
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075c65f74 6 bytes [68, 80, 41, 5B, 75, C3]
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075c750ed 6 bytes [68, 40, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075c7c701 6 bytes [68, C0, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e51401 2 bytes JMP 7787b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e51419 2 bytes JMP 7787b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e51431 2 bytes JMP 778f8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e5144a 2 bytes CALL 7785489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e514dd 2 bytes JMP 778f8822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e514f5 2 bytes JMP 778f89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e5150d 2 bytes JMP 778f8718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e51525 2 bytes JMP 778f8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e5153d 2 bytes JMP 7786fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e51555 2 bytes JMP 778768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e5156d 2 bytes JMP 778f8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e51585 2 bytes JMP 778f8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e5159d 2 bytes JMP 778f86dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e515b5 2 bytes JMP 7786fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e515cd 2 bytes JMP 7787b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e516b2 2 bytes JMP 778f8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Zemana AntiLogger Free\AntiLogger Free.exe[3584] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e516bd 2 bytes JMP 778f8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075c578e2 6 bytes [68, E0, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075c57bd3 6 bytes [68, 40, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075c605ba 6 bytes [68, 30, 42, 5B, 75, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075c65f74 6 bytes [68, 80, 41, 5B, 75, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075c750ed 6 bytes [68, 40, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075c7c701 6 bytes [68, C0, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e51401 2 bytes JMP 7787b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e51419 2 bytes JMP 7787b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e51431 2 bytes JMP 778f8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e5144a 2 bytes CALL 7785489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e514dd 2 bytes JMP 778f8822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e514f5 2 bytes JMP 778f89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e5150d 2 bytes JMP 778f8718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e51525 2 bytes JMP 778f8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e5153d 2 bytes JMP 7786fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e51555 2 bytes JMP 778768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e5156d 2 bytes JMP 778f8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e51585 2 bytes JMP 778f8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e5159d 2 bytes JMP 778f86dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e515b5 2 bytes JMP 7786fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e515cd 2 bytes JMP 7787b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e516b2 2 bytes JMP 778f8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[3600] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e516bd 2 bytes JMP 778f8671 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075c578e2 6 bytes [68, E0, 40, 5B, 75, C3]
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075c57bd3 6 bytes [68, 40, 40, 5B, 75, C3]
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075c605ba 6 bytes [68, 30, 42, 5B, 75, C3]
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075c65f74 6 bytes [68, 80, 41, 5B, 75, C3]
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075c750ed 6 bytes [68, 40, 3F, 5B, 75, C3]
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075c7c701 6 bytes [68, C0, 3F, 5B, 75, C3]
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e51401 2 bytes JMP 7787b21b C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e51419 2 bytes JMP 7787b346 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e51431 2 bytes JMP 778f8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e5144a 2 bytes CALL 7785489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e514dd 2 bytes JMP 778f8822 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e514f5 2 bytes JMP 778f89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e5150d 2 bytes JMP 778f8718 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e51525 2 bytes JMP 778f8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e5153d 2 bytes JMP 7786fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e51555 2 bytes JMP 778768ef C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e5156d 2 bytes JMP 778f8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e51585 2 bytes JMP 778f8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e5159d 2 bytes JMP 778f86dc C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e515b5 2 bytes JMP 7786fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e515cd 2 bytes JMP 7787b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e516b2 2 bytes JMP 778f8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Windows\SysWOW64\vmnetdhcp.exe[3652] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e516bd 2 bytes JMP 778f8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4172] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077bfde30 16 bytes [50, 48, B8, 34, 35, 69, F7, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4172] C:\Windows\system32\USER32.dll!PeekMessageA 0000000077ac3a18 14 bytes [68, 30, 43, 8C, FD, C7, 44, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4172] C:\Windows\system32\USER32.dll!GetMessageA 0000000077ac6110 14 bytes [68, 30, 42, 8C, FD, C7, 44, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4172] C:\Windows\system32\USER32.dll!IsDialogMessageW 0000000077ac66c0 14 bytes [68, F0, 41, 8C, FD, C7, 44, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4172] C:\Windows\system32\USER32.dll!PeekMessageW 0000000077ac8fd0 14 bytes [68, D0, 43, 8C, FD, C7, 44, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4172] C:\Windows\system32\USER32.dll!GetMessageW 0000000077ac9e74 14 bytes [68, B0, 42, 8C, FD, C7, 44, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4172] C:\Windows\system32\USER32.dll!IsDialogMessage 0000000077b03268 14 bytes [68, B0, 41, 8C, FD, C7, 44, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077bfdc80 16 bytes [50, 48, B8, 4C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 0000000077bfddf0 16 bytes [50, 48, B8, A4, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077bfde10 48 bytes [50, 48, B8, 20, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077bfde50 16 bytes [50, 48, B8, 70, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 0000000077bfdea0 32 bytes [50, 48, B8, C8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077bfdee0 16 bytes [50, 48, B8, B0, EE, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 0000000077bfdf80 16 bytes [50, 48, B8, F8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077bfe100 16 bytes [50, 48, B8, 74, ED, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 0000000077bfeb70 16 bytes [50, 48, B8, 44, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077bfebc0 16 bytes [50, 48, B8, 80, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1272] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 0000000077bfed10 16 bytes [50, 48, B8, 0C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5248] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077bfdc80 16 bytes [50, 48, B8, 4C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5248] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 0000000077bfddf0 16 bytes [50, 48, B8, A4, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5248] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077bfde10 48 bytes [50, 48, B8, 20, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5248] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077bfde50 16 bytes [50, 48, B8, 70, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5248] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 0000000077bfdea0 32 bytes [50, 48, B8, C8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5248] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077bfdee0 16 bytes [50, 48, B8, B0, EE, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5248] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 0000000077bfdf80 16 bytes [50, 48, B8, F8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5248] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077bfe100 16 bytes [50, 48, B8, 74, ED, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5248] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 0000000077bfeb70 16 bytes [50, 48, B8, 44, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5248] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077bfebc0 16 bytes [50, 48, B8, 80, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5248] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 0000000077bfed10 16 bytes [50, 48, B8, 0C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5272] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077bfdc80 16 bytes [50, 48, B8, 4C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 0000000077bfddf0 16 bytes [50, 48, B8, A4, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077bfde10 48 bytes [50, 48, B8, 20, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5272] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077bfde50 16 bytes [50, 48, B8, 70, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 0000000077bfdea0 32 bytes [50, 48, B8, C8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077bfdee0 16 bytes [50, 48, B8, B0, EE, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5272] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 0000000077bfdf80 16 bytes [50, 48, B8, F8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5272] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077bfe100 16 bytes [50, 48, B8, 74, ED, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 0000000077bfeb70 16 bytes [50, 48, B8, 44, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5272] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077bfebc0 16 bytes [50, 48, B8, 80, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5272] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 0000000077bfed10 16 bytes [50, 48, B8, 0C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5280] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077bfdc80 16 bytes [50, 48, B8, 4C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 0000000077bfddf0 16 bytes [50, 48, B8, A4, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077bfde10 48 bytes [50, 48, B8, 20, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5280] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077bfde50 16 bytes [50, 48, B8, 70, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 0000000077bfdea0 32 bytes [50, 48, B8, C8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077bfdee0 16 bytes [50, 48, B8, B0, EE, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5280] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 0000000077bfdf80 16 bytes [50, 48, B8, F8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5280] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077bfe100 16 bytes [50, 48, B8, 74, ED, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 0000000077bfeb70 16 bytes [50, 48, B8, 44, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5280] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077bfebc0 16 bytes [50, 48, B8, 80, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5280] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 0000000077bfed10 16 bytes [50, 48, B8, 0C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5316] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077bfdc80 16 bytes [50, 48, B8, 4C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5316] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 0000000077bfddf0 16 bytes [50, 48, B8, A4, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5316] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077bfde10 48 bytes [50, 48, B8, 20, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5316] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077bfde50 16 bytes [50, 48, B8, 70, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5316] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 0000000077bfdea0 32 bytes [50, 48, B8, C8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5316] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077bfdee0 16 bytes [50, 48, B8, B0, EE, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5316] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 0000000077bfdf80 16 bytes [50, 48, B8, F8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5316] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077bfe100 16 bytes [50, 48, B8, 74, ED, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5316] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 0000000077bfeb70 16 bytes [50, 48, B8, 44, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5316] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077bfebc0 16 bytes [50, 48, B8, 80, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[5316] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 0000000077bfed10 16 bytes [50, 48, B8, 0C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075c578e2 6 bytes [68, E0, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075c57bd3 6 bytes [68, 40, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075c605ba 6 bytes [68, 30, 42, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075c65f74 6 bytes [68, 80, 41, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075c750ed 6 bytes [68, 40, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075c7c701 6 bytes [68, C0, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e51401 2 bytes JMP 7787b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e51419 2 bytes JMP 7787b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e51431 2 bytes JMP 778f8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e5144a 2 bytes CALL 7785489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e514dd 2 bytes JMP 778f8822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e514f5 2 bytes JMP 778f89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e5150d 2 bytes JMP 778f8718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e51525 2 bytes JMP 778f8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e5153d 2 bytes JMP 7786fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e51555 2 bytes JMP 778768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e5156d 2 bytes JMP 778f8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e51585 2 bytes JMP 778f8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e5159d 2 bytes JMP 778f86dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e515b5 2 bytes JMP 7786fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e515cd 2 bytes JMP 7787b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e516b2 2 bytes JMP 778f8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe[6092] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e516bd 2 bytes JMP 778f8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075c578e2 6 bytes [68, E0, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075c57bd3 6 bytes [68, 40, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075c605ba 6 bytes [68, 30, 42, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075c65f74 6 bytes [68, 80, 41, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075c750ed 6 bytes [68, 40, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075c7c701 6 bytes [68, C0, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e51401 2 bytes JMP 7787b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e51419 2 bytes JMP 7787b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e51431 2 bytes JMP 778f8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e5144a 2 bytes CALL 7785489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e514dd 2 bytes JMP 778f8822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e514f5 2 bytes JMP 778f89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e5150d 2 bytes JMP 778f8718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e51525 2 bytes JMP 778f8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e5153d 2 bytes JMP 7786fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e51555 2 bytes JMP 778768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e5156d 2 bytes JMP 778f8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e51585 2 bytes JMP 778f8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e5159d 2 bytes JMP 778f86dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e515b5 2 bytes JMP 7786fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e515cd 2 bytes JMP 7787b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e516b2 2 bytes JMP 778f8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[5832] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e516bd 2 bytes JMP 778f8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075c578e2 6 bytes [68, E0, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075c57bd3 6 bytes [68, 40, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075c605ba 6 bytes [68, 30, 42, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075c65f74 6 bytes [68, 80, 41, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075c750ed 6 bytes [68, 40, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075c7c701 6 bytes [68, C0, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e51401 2 bytes JMP 7787b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e51419 2 bytes JMP 7787b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e51431 2 bytes JMP 778f8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e5144a 2 bytes CALL 7785489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e514dd 2 bytes JMP 778f8822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e514f5 2 bytes JMP 778f89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e5150d 2 bytes JMP 778f8718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e51525 2 bytes JMP 778f8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e5153d 2 bytes JMP 7786fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e51555 2 bytes JMP 778768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e5156d 2 bytes JMP 778f8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e51585 2 bytes JMP 778f8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e5159d 2 bytes JMP 778f86dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e515b5 2 bytes JMP 7786fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e515cd 2 bytes JMP 7787b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e516b2 2 bytes JMP 778f8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[3504] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e516bd 2 bytes JMP 778f8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075c578e2 6 bytes [68, E0, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075c57bd3 6 bytes [68, 40, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075c605ba 6 bytes [68, 30, 42, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075c65f74 6 bytes [68, 80, 41, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075c750ed 6 bytes [68, 40, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075c7c701 6 bytes [68, C0, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e51401 2 bytes JMP 7787b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e51419 2 bytes JMP 7787b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e51431 2 bytes JMP 778f8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e5144a 2 bytes CALL 7785489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e514dd 2 bytes JMP 778f8822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e514f5 2 bytes JMP 778f89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e5150d 2 bytes JMP 778f8718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e51525 2 bytes JMP 778f8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e5153d 2 bytes JMP 7786fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e51555 2 bytes JMP 778768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e5156d 2 bytes JMP 778f8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e51585 2 bytes JMP 778f8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e5159d 2 bytes JMP 778f86dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e515b5 2 bytes JMP 7786fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e515cd 2 bytes JMP 7787b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e516b2 2 bytes JMP 778f8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[5212] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e516bd 2 bytes JMP 778f8671 C:\Windows\syswow64\kernel32.dll
? C:\Windows\system32\mssprxy.dll [5212] entry point in ".rdata" section 0000000061ae71e6
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075c578e2 6 bytes [68, E0, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075c57bd3 6 bytes [68, 40, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075c605ba 6 bytes [68, 30, 42, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075c65f74 6 bytes [68, 80, 41, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075c750ed 6 bytes [68, 40, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075c7c701 6 bytes [68, C0, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e51401 2 bytes JMP 7787b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e51419 2 bytes JMP 7787b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e51431 2 bytes JMP 778f8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e5144a 2 bytes CALL 7785489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e514dd 2 bytes JMP 778f8822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e514f5 2 bytes JMP 778f89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e5150d 2 bytes JMP 778f8718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e51525 2 bytes JMP 778f8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e5153d 2 bytes JMP 7786fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e51555 2 bytes JMP 778768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e5156d 2 bytes JMP 778f8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e51585 2 bytes JMP 778f8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e5159d 2 bytes JMP 778f86dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e515b5 2 bytes JMP 7786fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e515cd 2 bytes JMP 7787b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e516b2 2 bytes JMP 778f8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4632] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e516bd 2 bytes JMP 778f8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075c578e2 6 bytes [68, E0, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075c57bd3 6 bytes [68, 40, 40, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075c605ba 6 bytes [68, 30, 42, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075c65f74 6 bytes [68, 80, 41, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075c750ed 6 bytes [68, 40, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075c7c701 6 bytes [68, C0, 3F, 5B, 75, C3]
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e51401 2 bytes JMP 7787b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e51419 2 bytes JMP 7787b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e51431 2 bytes JMP 778f8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e5144a 2 bytes CALL 7785489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e514dd 2 bytes JMP 778f8822 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e514f5 2 bytes JMP 778f89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e5150d 2 bytes JMP 778f8718 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e51525 2 bytes JMP 778f8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e5153d 2 bytes JMP 7786fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e51555 2 bytes JMP 778768ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e5156d 2 bytes JMP 778f8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e51585 2 bytes JMP 778f8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e5159d 2 bytes JMP 778f86dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e515b5 2 bytes JMP 7786fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e515cd 2 bytes JMP 7787b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e516b2 2 bytes JMP 778f8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Netease\CloudMusic\cloudmusic.exe[4040] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e516bd 2 bytes JMP 778f8671 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3520] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077bfdc80 16 bytes [50, 48, B8, 4C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 0000000077bfddf0 16 bytes [50, 48, B8, A4, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077bfde10 48 bytes [50, 48, B8, 20, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3520] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077bfde50 16 bytes [50, 48, B8, 70, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 0000000077bfdea0 32 bytes [50, 48, B8, C8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077bfdee0 16 bytes [50, 48, B8, B0, EE, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3520] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 0000000077bfdf80 16 bytes [50, 48, B8, F8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3520] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077bfe100 16 bytes [50, 48, B8, 74, ED, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 0000000077bfeb70 16 bytes [50, 48, B8, 44, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3520] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077bfebc0 16 bytes [50, 48, B8, 80, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[3520] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 0000000077bfed10 16 bytes [50, 48, B8, 0C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7780] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077bfdc80 16 bytes [50, 48, B8, 4C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 0000000077bfddf0 16 bytes [50, 48, B8, A4, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077bfde10 48 bytes [50, 48, B8, 20, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7780] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077bfde50 16 bytes [50, 48, B8, 70, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 0000000077bfdea0 32 bytes [50, 48, B8, C8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077bfdee0 16 bytes [50, 48, B8, B0, EE, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7780] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 0000000077bfdf80 16 bytes [50, 48, B8, F8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7780] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077bfe100 16 bytes [50, 48, B8, 74, ED, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 0000000077bfeb70 16 bytes [50, 48, B8, 44, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7780] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077bfebc0 16 bytes [50, 48, B8, 80, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7780] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 0000000077bfed10 16 bytes [50, 48, B8, 0C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4476] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077bfdc80 16 bytes [50, 48, B8, 4C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4476] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 0000000077bfddf0 16 bytes [50, 48, B8, A4, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4476] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077bfde10 48 bytes [50, 48, B8, 20, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4476] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077bfde50 16 bytes [50, 48, B8, 70, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4476] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 0000000077bfdea0 32 bytes [50, 48, B8, C8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4476]
C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077bfdee0 16 bytes [50, 48, B8, B0, EE, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4476] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 0000000077bfdf80 16 bytes [50, 48, B8, F8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4476] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077bfe100 16 bytes [50, 48, B8, 74, ED, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4476] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 0000000077bfeb70 16 bytes [50, 48, B8, 44, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4476] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077bfebc0 16 bytes [50, 48, B8, 80, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[4476] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 0000000077bfed10 16 bytes [50, 48, B8, 0C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1860] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077bfdc80 16 bytes [50, 48, B8, 4C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 0000000077bfddf0 16 bytes [50, 48, B8, A4, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077bfde10 48 bytes [50, 48, B8, 20, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1860] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077bfde50 16 bytes [50, 48, B8, 70, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 0000000077bfdea0 32 bytes [50, 48, B8, C8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077bfdee0 16 bytes [50, 48, B8, B0, EE, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1860] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 0000000077bfdf80 16 bytes [50, 48, B8, F8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1860] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077bfe100 16 bytes [50, 48, B8, 74, ED, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 0000000077bfeb70 16 bytes [50, 48, B8, 44, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1860] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077bfebc0 16 bytes [50, 48, B8, 80, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[1860] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 0000000077bfed10 16 bytes [50, 48, B8, 0C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7628] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077bfdc80 16 bytes [50, 48, B8, 4C, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadToken 0000000077bfddf0 16 bytes [50, 48, B8, A4, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077bfde10 48 bytes [50, 48, B8, 20, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7628] C:\Windows\SYSTEM32\ntdll.dll!NtUnmapViewOfSection 0000000077bfde50 16 bytes [50, 48, B8, 70, F0, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThreadTokenEx 0000000077bfdea0 32 bytes [50, 48, B8, C8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077bfdee0 16 bytes [50, 48, B8, B0, EE, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7628] C:\Windows\SYSTEM32\ntdll.dll!NtQueryAttributesFile 0000000077bfdf80 16 bytes [50, 48, B8, F8, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077bfe100 16 bytes [50, 48, B8, 74, ED, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcessToken 0000000077bfeb70 16 bytes [50, 48, B8, 44, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077bfebc0 16 bytes [50, 48, B8, 80, EF, 57, 3F, ...]
.text C:\Program Files (x86)\Google\Chrome\Application\chrome.exe[7628] C:\Windows\SYSTEM32\ntdll.dll!NtQueryFullAttributesFile 0000000077bfed10 16 bytes [50, 48, B8, 0C, F0, 57, 3F, ...]
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\USER32.dll!GetMessageW 0000000075c578e2 6 bytes [68, E0, 40, 5B, 75, C3]
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\USER32.dll!GetMessageA 0000000075c57bd3 6 bytes [68, 40, 40, 5B, 75, C3]
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\USER32.dll!PeekMessageW 0000000075c605ba 6 bytes [68, 30, 42, 5B, 75, C3]
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\USER32.dll!PeekMessageA 0000000075c65f74 6 bytes [68, 80, 41, 5B, 75, C3]
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\USER32.dll!IsDialogMessage 0000000075c750ed 6 bytes [68, 40, 3F, 5B, 75, C3]
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\USER32.dll!IsDialogMessageW 0000000075c7c701 6 bytes [68, C0, 3F, 5B, 75, C3]
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075e51401 2 bytes JMP 7787b21b C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075e51419 2 bytes JMP 7787b346 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075e51431 2 bytes JMP 778f8f29 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000075e5144a 2 bytes CALL 7785489d C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000075e514dd 2 bytes JMP 778f8822 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000075e514f5 2 bytes JMP 778f89f8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000075e5150d 2 bytes JMP 778f8718 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075e51525 2 bytes JMP 778f8ae2 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000075e5153d 2 bytes JMP 7786fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075e51555 2 bytes JMP 778768ef C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000075e5156d 2 bytes JMP 778f8fe3 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075e51585 2 bytes JMP 778f8b42 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000075e5159d 2 bytes JMP 778f86dc C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000075e515b5 2 bytes JMP 7786fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000075e515cd 2 bytes JMP 7787b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000075e516b2 2 bytes JMP 778f8ea4 C:\Windows\syswow64\kernel32.dll
.text C:\Users\Admin\Downloads\d3zrc5te.exe[7936] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000075e516bd 2 bytes JMP 778f8671 C:\Windows\syswow64\kernel32.dll
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk1\DR1 unknown MBR code
---- EOF - GMER 2.1 ---- |