KokomikoM | 01.11.2015 11:00 | Gmer Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-10-29 08:58:12
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD10EARS-22Y5B1 rev.80.00A80 931,51GB
Running: Gmer-19357.exe; Driver: C:\Users\Conny\AppData\Local\Temp\pwriypod.sys
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwReplaceKey + 1525 82C47B55 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82C81BB2 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [89, 71]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [8C, 71]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [86, 71]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [80, 71]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [83, 71]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [8F, 71]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [77, 71] {JA 0x73}
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1296] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Windows\system32\taskeng.exe[1296] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 7172000A
.text C:\Windows\system32\taskeng.exe[1296] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1296] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [74, 71] {JZ 0x73}
.text C:\Windows\system32\taskeng.exe[1296] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 71A2000A
.text C:\Windows\system32\taskeng.exe[1296] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 719C000A
.text C:\Windows\system32\taskeng.exe[1296] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7199000A
.text C:\Windows\system32\taskeng.exe[1296] USER32.dll!SendMessageW 77615539 6 Bytes JMP 719F000A
.text C:\Windows\system32\taskeng.exe[1296] USER32.dll!mouse_event 77626209 6 Bytes JMP 71AB000A
.text C:\Windows\system32\taskeng.exe[1296] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[1296] USER32.dll!SendInput + 4 7763701D 2 Bytes [A4, 71]
.text C:\Windows\system32\taskeng.exe[1296] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 71A8000A
.text C:\Windows\system32\taskeng.exe[1296] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 7193000A
.text C:\Windows\system32\taskeng.exe[1296] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7196000A
.text C:\Program Files\Emsisoft Anti-Malware\a2service.exe[1368] ntdll.dll!RtlFreeActivationContextStack + 44 776FF5F6 7 Bytes JMP 0961B734 C:\Program Files\Emsisoft Anti-Malware\a2update.dll
.text C:\Program Files\Emsisoft Anti-Malware\a2service.exe[1368] kernel32.dll!GetSystemInfo + B 75BEDDBD 7 Bytes JMP 0961B520 C:\Program Files\Emsisoft Anti-Malware\a2update.dll
.text C:\Program Files\Emsisoft Anti-Malware\a2service.exe[1368] kernel32.dll!GetSystemTime + B 75BEEB5C 7 Bytes JMP 095BB3CC C:\Program Files\Emsisoft Anti-Malware\a2update.dll
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [89, 71]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [8C, 71]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [86, 71]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [80, 71]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [83, 71]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [8F, 71]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [77, 71] {JA 0x73}
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 7172000A
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [74, 71] {JZ 0x73}
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 71A2000A
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 719C000A
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7199000A
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] USER32.dll!SendMessageW 77615539 6 Bytes JMP 719F000A
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] USER32.dll!mouse_event 77626209 6 Bytes JMP 71AB000A
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] USER32.dll!SendInput + 4 7763701D 2 Bytes [A4, 71]
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 71A8000A
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 7193000A
.text C:\Users\Meggle\Downloads\Gmer-19357.exe[2164] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7196000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [71, 71] {JNO 0x73}
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [6B, 71]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [68, 71]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [6E, 71]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [62, 71]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [65, 71]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 715D000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [5F, 71]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] WS2_32.dll!WSALookupServiceBeginW 75B4575A 6 Bytes JMP 7199000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] WS2_32.dll!connect 75B46BDD 6 Bytes JMP 71A2000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] WS2_32.dll!listen 75B4B001 6 Bytes JMP 719C000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] WS2_32.dll!WSAConnect 75B4CC3F 6 Bytes JMP 719F000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 718D000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 7187000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7184000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] USER32.dll!SendMessageW 77615539 6 Bytes JMP 718A000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] USER32.dll!mouse_event 77626209 6 Bytes JMP 7196000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] USER32.dll!SendInput + 4 7763701D 2 Bytes [8F, 71]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 7193000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 717E000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe[2228] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7181000A
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [89, 71]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [8C, 71]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [86, 71]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [80, 71]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [83, 71]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [8F, 71]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [77, 71] {JA 0x73}
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[2288] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Windows\system32\taskhost.exe[2288] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 7172000A
.text C:\Windows\system32\taskhost.exe[2288] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[2288] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [74, 71] {JZ 0x73}
.text C:\Windows\system32\taskhost.exe[2288] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 71A2000A
.text C:\Windows\system32\taskhost.exe[2288] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 719C000A
.text C:\Windows\system32\taskhost.exe[2288] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7199000A
.text C:\Windows\system32\taskhost.exe[2288] USER32.dll!SendMessageW 77615539 6 Bytes JMP 719F000A
.text C:\Windows\system32\taskhost.exe[2288] USER32.dll!mouse_event 77626209 6 Bytes JMP 71AB000A
.text C:\Windows\system32\taskhost.exe[2288] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskhost.exe[2288] USER32.dll!SendInput + 4 7763701D 2 Bytes [A4, 71]
.text C:\Windows\system32\taskhost.exe[2288] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 71A8000A
.text C:\Windows\system32\taskhost.exe[2288] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 7193000A
.text C:\Windows\system32\taskhost.exe[2288] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7196000A
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [89, 71]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [8C, 71]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [86, 71]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [80, 71]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [83, 71]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [8F, 71]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [77, 71] {JA 0x73}
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2372] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Windows\system32\Dwm.exe[2372] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 7172000A
.text C:\Windows\system32\Dwm.exe[2372] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2372] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [74, 71] {JZ 0x73}
.text C:\Windows\system32\Dwm.exe[2372] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 71A2000A
.text C:\Windows\system32\Dwm.exe[2372] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 719C000A
.text C:\Windows\system32\Dwm.exe[2372] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7199000A
.text C:\Windows\system32\Dwm.exe[2372] USER32.dll!SendMessageW 77615539 6 Bytes JMP 719F000A
.text C:\Windows\system32\Dwm.exe[2372] USER32.dll!mouse_event 77626209 6 Bytes JMP 71AB000A
.text C:\Windows\system32\Dwm.exe[2372] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[2372] USER32.dll!SendInput + 4 7763701D 2 Bytes [A4, 71]
.text C:\Windows\system32\Dwm.exe[2372] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 71A8000A
.text C:\Windows\system32\Dwm.exe[2372] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 7193000A
.text C:\Windows\system32\Dwm.exe[2372] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7196000A
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [83, 71]
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [86, 71]
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [80, 71]
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [7A, 71] {JP 0x73}
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [77, 71] {JA 0x73}
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [89, 71]
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [71, 71] {JNO 0x73}
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[2396] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [74, 71] {JZ 0x73}
.text C:\Windows\System32\rundll32.exe[2396] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 716C000A
.text C:\Windows\System32\rundll32.exe[2396] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[2396] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [6E, 71]
.text C:\Windows\System32\rundll32.exe[2396] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 719C000A
.text C:\Windows\System32\rundll32.exe[2396] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 7196000A
.text C:\Windows\System32\rundll32.exe[2396] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7193000A
.text C:\Windows\System32\rundll32.exe[2396] USER32.dll!SendMessageW 77615539 6 Bytes JMP 7199000A
.text C:\Windows\System32\rundll32.exe[2396] USER32.dll!mouse_event 77626209 6 Bytes JMP 71A5000A
.text C:\Windows\System32\rundll32.exe[2396] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[2396] USER32.dll!SendInput + 4 7763701D 2 Bytes [9E, 71]
.text C:\Windows\System32\rundll32.exe[2396] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 71A2000A
.text C:\Windows\System32\rundll32.exe[2396] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 718D000A
.text C:\Windows\System32\rundll32.exe[2396] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7190000A
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [89, 71]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [8C, 71]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [86, 71]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [80, 71]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [83, 71]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [8F, 71]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [77, 71] {JA 0x73}
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2568] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Windows\Explorer.EXE[2568] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 7172000A
.text C:\Windows\Explorer.EXE[2568] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2568] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [74, 71] {JZ 0x73}
.text C:\Windows\Explorer.EXE[2568] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 7193000A
.text C:\Windows\Explorer.EXE[2568] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7196000A
.text C:\Windows\Explorer.EXE[2568] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 71A2000A
.text C:\Windows\Explorer.EXE[2568] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 719C000A
.text C:\Windows\Explorer.EXE[2568] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7199000A
.text C:\Windows\Explorer.EXE[2568] USER32.dll!SendMessageW 77615539 6 Bytes JMP 719F000A
.text C:\Windows\Explorer.EXE[2568] USER32.dll!mouse_event 77626209 6 Bytes JMP 71AB000A
.text C:\Windows\Explorer.EXE[2568] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Windows\Explorer.EXE[2568] USER32.dll!SendInput + 4 7763701D 2 Bytes [A4, 71]
.text C:\Windows\Explorer.EXE[2568] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 71A8000A
.text C:\Windows\Explorer.EXE[2568] WS2_32.dll!WSALookupServiceBeginW 75B4575A 6 Bytes JMP 7157000A
.text C:\Windows\Explorer.EXE[2568] WS2_32.dll!connect 75B46BDD 6 Bytes JMP 7160000A
.text C:\Windows\Explorer.EXE[2568] WS2_32.dll!listen 75B4B001 6 Bytes JMP 715A000A
.text C:\Windows\Explorer.EXE[2568] WS2_32.dll!WSAConnect 75B4CC3F 6 Bytes JMP 715D000A
.text C:\Program Files\Emsisoft Anti-Malware\a2guard.exe[2980] ntdll.dll!RtlFreeActivationContextStack + 44 776FF5F6 7 Bytes JMP 03C10890 C:\Program Files\Emsisoft Anti-Malware\a2framework.dll
.text C:\Program Files\Emsisoft Anti-Malware\a2guard.exe[2980] kernel32.dll!GetSystemInfo + B 75BEDDBD 7 Bytes JMP 03C1067C C:\Program Files\Emsisoft Anti-Malware\a2framework.dll
.text C:\Program Files\Emsisoft Anti-Malware\a2guard.exe[2980] kernel32.dll!GetSystemTime + B 75BEEB5C 7 Bytes JMP 03BABEF8 C:\Program Files\Emsisoft Anti-Malware\a2framework.dll
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [89, 71]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [8C, 71]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [86, 71]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [80, 71]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [83, 71]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [8F, 71]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 7172000A
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 71A2000A
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 719C000A
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7199000A
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] USER32.dll!SendMessageW 77615539 6 Bytes JMP 719F000A
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] USER32.dll!mouse_event 77626209 6 Bytes JMP 71AB000A
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] USER32.dll!SendInput + 4 7763701D 2 Bytes [A4, 71]
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 71A8000A
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 7193000A
.text C:\Program Files\Hp\HP Software Update\hpwuschd2.exe[2992] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7196000A
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [89, 71]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [8C, 71]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [86, 71]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [80, 71]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [83, 71]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [8F, 71]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 7172000A
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 71A2000A
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 719C000A
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7199000A
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] USER32.dll!SendMessageW 77615539 6 Bytes JMP 719F000A
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] USER32.dll!mouse_event 77626209 6 Bytes JMP 71AB000A
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] USER32.dll!SendInput + 4 7763701D 2 Bytes [A4, 71]
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 71A8000A
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 7193000A
.text C:\Program Files\FreePDF_XP\fpassist.exe[3016] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7196000A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [80, 71]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [83, 71]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [7A, 71] {JP 0x73}
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [86, 71]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [6E, 71]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [71, 71] {JNO 0x73}
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 7169000A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [6B, 71]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 7199000A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 7193000A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7190000A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] USER32.dll!SendMessageW 77615539 6 Bytes JMP 7196000A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] USER32.dll!mouse_event 77626209 6 Bytes JMP 71A2000A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] USER32.dll!SendInput + 4 7763701D 2 Bytes [9B, 71]
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 719F000A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] advapi32.DLL!CreateServiceW 762B70C4 6 Bytes JMP 718A000A
.text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3040] advapi32.DLL!CreateServiceA 762D3264 6 Bytes JMP 718D000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [71, 71] {JNO 0x73}
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [6B, 71]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [68, 71]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [6E, 71]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [62, 71]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [65, 71]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 715D000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [5F, 71]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 718D000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 7187000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7184000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] USER32.dll!SendMessageW 77615539 6 Bytes JMP 718A000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] USER32.dll!mouse_event 77626209 6 Bytes JMP 7196000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] USER32.dll!SendInput + 4 7763701D 2 Bytes [8F, 71]
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 7193000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 717E000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7181000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] WS2_32.dll!WSALookupServiceBeginW 75B4575A 6 Bytes JMP 7199000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] WS2_32.dll!connect 75B46BDD 6 Bytes JMP 71A2000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] WS2_32.dll!listen 75B4B001 6 Bytes JMP 719C000A
.text C:\Program Files\Hp\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe[3084] WS2_32.dll!WSAConnect 75B4CC3F 6 Bytes JMP 719F000A
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [71, 71] {JNO 0x73}
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [6B, 71]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [68, 71]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [6E, 71]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [62, 71]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [65, 71]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 715D000A
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [5F, 71]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 718D000A
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 7187000A
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7184000A
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] USER32.dll!SendMessageW 77615539 6 Bytes JMP 718A000A
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] USER32.dll!mouse_event 77626209 6 Bytes JMP 7196000A
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] USER32.dll!SendInput + 4 7763701D 2 Bytes [8F, 71]
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 7193000A
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 717E000A
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7181000A
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] WS2_32.dll!WSALookupServiceBeginW 75B4575A 6 Bytes JMP 7199000A
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] WS2_32.dll!connect 75B46BDD 6 Bytes JMP 71A2000A
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] WS2_32.dll!listen 75B4B001 6 Bytes JMP 719C000A
.text C:\Program Files\Belkin\Network USB Hub Control Center\Connect.exe[3104] WS2_32.dll!WSAConnect 75B4CC3F 6 Bytes JMP 719F000A
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [89, 71]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [8C, 71]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [86, 71]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [80, 71]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [83, 71]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [8F, 71]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 7172000A
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 71A2000A
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 719C000A
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7199000A
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] USER32.dll!SendMessageW 77615539 6 Bytes JMP 719F000A
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] USER32.dll!mouse_event 77626209 6 Bytes JMP 71AB000A
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] USER32.dll!SendInput + 4 7763701D 2 Bytes [A4, 71]
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 71A8000A
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 7193000A
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7196000A
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] WS2_32.dll!WSALookupServiceBeginW 75B4575A 6 Bytes JMP 7166000A
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] WS2_32.dll!connect 75B46BDD 6 Bytes JMP 716F000A
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] WS2_32.dll!listen 75B4B001 6 Bytes JMP 7169000A
.text C:\Program Files\Easy2Sync\Easy2Sync.exe[3188] WS2_32.dll!WSAConnect 75B4CC3F 6 Bytes JMP 716C000A
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [83, 71]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [86, 71]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [80, 71]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [7A, 71] {JP 0x73}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [89, 71]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [71, 71] {JNO 0x73}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 716C000A
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [6E, 71]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 718D000A
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7190000A
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 719C000A
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 7196000A
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7193000A
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] USER32.dll!SendMessageW 77615539 6 Bytes JMP 7199000A
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] USER32.dll!mouse_event 77626209 6 Bytes JMP 71A5000A
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] USER32.dll!SendInput + 4 7763701D 2 Bytes [9E, 71]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 71A2000A
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] WS2_32.dll!WSALookupServiceBeginW 75B4575A 6 Bytes JMP 7160000A
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] WS2_32.dll!connect 75B46BDD 6 Bytes JMP 7169000A
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] WS2_32.dll!listen 75B4B001 6 Bytes JMP 7163000A
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[3428] WS2_32.dll!WSAConnect 75B4CC3F 6 Bytes JMP 7166000A
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [71, 71] {JNO 0x73}
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [6E, 71]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [80, 71]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [68, 71]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [6B, 71]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 7163000A
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [65, 71]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] WS2_32.dll!WSALookupServiceBeginW 75B4575A 6 Bytes JMP 719F000A
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] WS2_32.dll!connect 75B46BDD 6 Bytes JMP 71AB000A
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] WS2_32.dll!listen 75B4B001 6 Bytes JMP 71A2000A
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] WS2_32.dll!WSAConnect 75B4CC3F 6 Bytes JMP 71A5000A
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 7193000A
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 718D000A
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 718A000A
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] USER32.dll!SendMessageW 77615539 6 Bytes JMP 7190000A
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] USER32.dll!mouse_event 77626209 6 Bytes JMP 719C000A
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] USER32.dll!SendInput + 4 7763701D 2 Bytes [95, 71]
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 7199000A
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 7184000A
.text C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe[3492] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7187000A
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [80, 71]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [83, 71]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [7A, 71] {JP 0x73}
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [86, 71]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [6E, 71]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [71, 71] {JNO 0x73}
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 7169000A
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [6B, 71]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 7199000A
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 7193000A
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 7190000A
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] USER32.dll!SendMessageW 77615539 6 Bytes JMP 7196000A
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] USER32.dll!mouse_event 77626209 6 Bytes JMP 71A2000A
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] USER32.dll!SendInput + 4 7763701D 2 Bytes [9B, 71]
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 719F000A
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] advapi32.DLL!CreateServiceW 762B70C4 6 Bytes JMP 718A000A
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] advapi32.DLL!CreateServiceA 762D3264 6 Bytes JMP 718D000A
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] WS2_32.dll!WSALookupServiceBeginW 75B4575A 6 Bytes JMP 715D000A
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] WS2_32.dll!connect 75B46BDD 6 Bytes JMP 7166000A
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] WS2_32.dll!listen 75B4B001 6 Bytes JMP 7160000A
.text C:\Program Files\Common Files\Java\Java Update\jucheck.exe[4320] WS2_32.dll!WSAConnect 75B4CC3F 6 Bytes JMP 7163000A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtCreateFile 777156B0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtCreateFile + 4 777156B4 2 Bytes [7A, 71] {JP 0x73}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtDeleteValueKey 77715930 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtDeleteValueKey + 4 77715934 2 Bytes [7D, 71] {JGE 0x73}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtOpenFile 77715DC0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtOpenFile + 4 77715DC4 2 Bytes [77, 71] {JA 0x73}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtOpenProcess 77715E70 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtOpenProcess + 4 77715E74 2 Bytes [71, 71] {JNO 0x73}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtSetContextThread 77716650 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtSetContextThread + 4 77716654 2 Bytes [6E, 71]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtSetInformationFile 77716720 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtSetInformationFile + 4 77716724 2 Bytes [74, 71] {JZ 0x73}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtSetValueKey 777168F0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtSetValueKey + 4 777168F4 2 Bytes [80, 71]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtSuspendThread 77716980 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtSuspendThread + 4 77716984 2 Bytes [68, 71]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtTerminateThread 777169C0 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ntdll.dll!NtTerminateThread + 4 777169C4 2 Bytes [6B, 71]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] kernel32.dll!TerminateProcess 75BE2D15 6 Bytes JMP 7163000A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] kernel32.dll!CreateProcessInternalW 75BF08A2 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] kernel32.dll!CreateProcessInternalW + 4 75BF08A6 2 Bytes [65, 71]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ADVAPI32.dll!CreateServiceW 762B70C4 6 Bytes JMP 7184000A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] ADVAPI32.dll!CreateServiceA 762D3264 6 Bytes JMP 7187000A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] USER32.dll!SendMessageA 7760AD60 6 Bytes JMP 7193000A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] USER32.dll!PostMessageA 7760B446 6 Bytes JMP 718D000A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] USER32.dll!PostMessageW 7761447B 6 Bytes JMP 718A000A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] USER32.dll!SendMessageW 77615539 6 Bytes JMP 7190000A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] USER32.dll!mouse_event 77626209 6 Bytes JMP 719C000A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] USER32.dll!SendInput 77637019 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] USER32.dll!SendInput + 4 7763701D 2 Bytes [95, 71]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[5220] USER32.dll!keybd_event 7765EC3B 6 Bytes JMP 7199000A
---- EOF - GMER 2.1 ---- Es gab keine Defrogger.txt |