Code:
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076705ea5 5 bytes JMP 00000001703c1618
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[3740] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076739d0b 5 bytes JMP 00000001703c123f
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076705ea5 5 bytes JMP 00000001703c1618
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076739d0b 5 bytes JMP 00000001703c123f
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69 0000000076f01465 2 bytes [F0, 76]
.text C:\Users\Grigorij\AppData\Roaming\Dropbox\bin\Dropbox.exe[4312] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155 0000000076f014bb 2 bytes [F0, 76]
.text ... * 2
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNEL32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076705ea5 5 bytes JMP 00000001703c1618
.text C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe[4484] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076739d0b 5 bytes JMP 00000001703c123f
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!RegSetValueExW 0000000076c3af40 7 bytes JMP 000000016fff0260
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW 0000000076c44a60 5 bytes JMP 000000016fff01b8
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW 0000000076c62990 5 bytes JMP 000000016fff01f0
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 0000000076c6efe0 5 bytes JMP 000000016fff0148
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 0000000076c999b0 7 bytes JMP 000000016fff00d8
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 0000000076ca94d0 5 bytes JMP 000000016fff0180
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!K32GetModuleFileNameExW 0000000076ca9640 5 bytes JMP 000000016fff0110
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 0000000076cca500 7 bytes JMP 000000016fff0228
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe137490 11 bytes JMP 000007fffcbd0228
.text C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe[3148] C:\Windows\system32\ole32.dll!CoSetProxyBlanket 000007fefe14bf00 7 bytes JMP 000007fffcbd0260
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076705ea5 5 bytes JMP 00000001703c1618
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe[4116] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076739d0b 5 bytes JMP 00000001703c123f
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076705ea5 5 bytes JMP 00000001703c1618
.text C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[4216] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076739d0b 5 bytes JMP 00000001703c123f
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076705ea5 5 bytes JMP 00000001703c1618
.text C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe[5144] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076739d0b 5 bytes JMP 00000001703c123f
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076705ea5 5 bytes JMP 00000001703c1618
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076739d0b 5 bytes JMP 00000001703c123f
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076f01465 2 bytes [F0, 76]
.text C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin[5188] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076f014bb 2 bytes [F0, 76]
.text ... * 2
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076705ea5 5 bytes JMP 00000001703c1618
.text C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe[5216] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076739d0b 5 bytes JMP 00000001703c123f
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076705ea5 5 bytes JMP 00000001703c1618
.text C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe[5240] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076739d0b 5 bytes JMP 00000001703c123f
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076705ea5 5 bytes JMP 00000001703c1618
.text C:\Program Files (x86)\CyberLink\Shared files\brs.exe[5364] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076739d0b 5 bytes JMP 00000001703c123f
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076705ea5 5 bytes JMP 00000001703c1618
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[5416] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076739d0b 5 bytes JMP 00000001703c123f
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076f01465 2 bytes [F0, 76]
.text C:\Program Files (x86)\Google\Drive\googledrivesync.exe[5520] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076f014bb 2 bytes [F0, 76]
.text ... * 2
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\ole32.dll!CoSetProxyBlanket 0000000076705ea5 5 bytes JMP 00000001703c1618
.text C:\Program Files (x86)\Duden\Duden-Bibliothek\dudenbib.exe[5248] C:\Windows\syswow64\ole32.dll!CoCreateInstance 0000000076739d0b 5 bytes JMP 00000001703c123f
.text C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!RegSetValueExW 0000000076c3af40 7 bytes JMP 000000016fff0260
.text C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!RegQueryValueExW 0000000076c44a60 5 bytes JMP 000000016fff01b8
.text C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!RegDeleteValueW 0000000076c62990 5 bytes JMP 000000016fff01f0
.text C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!K32GetMappedFileNameW 0000000076c6efe0 5 bytes JMP 000000016fff0148
.text C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!K32EnumProcessModulesEx 0000000076c999b0 7 bytes JMP 000000016fff00d8
.text C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!K32GetModuleInformation 0000000076ca94d0 5 bytes JMP 000000016fff0180
.text C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!K32GetModuleFileNameExW 0000000076ca9640 5 bytes JMP 000000016fff0110
.text C:\Windows\splwow64.exe[1772] C:\Windows\system32\kernel32.dll!RegSetValueExA 0000000076cca500 7 bytes JMP 000000016fff0228
.text C:\Windows\splwow64.exe[1772] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007fefcbe2db0 5 bytes JMP 000007fffcbd0180
.text C:\Windows\splwow64.exe[1772] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007fefcbe37d0 7 bytes JMP 000007fffcbd00d8
.text C:\Windows\splwow64.exe[1772] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefcbe8ef0 6 bytes JMP 000007fffcbd0148
.text C:\Windows\splwow64.exe[1772] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007fefcbfaf60 5 bytes JMP 000007fffcbd0110
.text C:\Windows\splwow64.exe[1772] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007fefe8c89e0 8 bytes JMP 000007fffcbd01f0
.text C:\Windows\splwow64.exe[1772] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007fefe8cbe40 8 bytes JMP 000007fffcbd01b8
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000747e13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000747e146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000747e16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessTerm + 3 00000000747e16e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000747e19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000747e19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetInstructionPointer + 23 00000000747e1a1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuNotifyAffinityChange + 3 00000000747e1a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000747e1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessDebugEvent + 3 00000000747e1a6f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Program Files (x86)\Steam\Steam.exe[5844] C:\Windows\syswow64\KERNELBASE.dll!HeapCreate 0000000075c2549c 5 bytes JMP 0000000100170800
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 5 0000000076d511f5 8 bytes {JMP 0xd}
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 416 0000000076d51390 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076d5143f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 492 0000000076d5158c 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076d5191e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 636 0000000076d51b1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 204 0000000076d51bf0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076d51d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 691 0000000076d51eb3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076d51edf 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!_ui64toa + 84 0000000076d51f64 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 81 0000000076d51fbd 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelf + 7 0000000076d51fd7 8 bytes {JMP 0xb}
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 658 0000000076d52272 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 801 0000000076d52301 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlInstallFunctionTableCallback + 578 0000000076d52792 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076d527b0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076d527d2 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076d5282f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 176 0000000076d52890 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076d52d1b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 367 0000000076d52d5f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlCutoverTimeToSystemTime + 483 0000000076d53023 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076d5323b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 912 0000000076d533c0 16 bytes {JMP 0x4e}
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076d53a5e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076d53ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076d53b85 8 bytes [10, 6A, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 611 0000000076d53d23 8 bytes [00, 6A, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076d54190 8 bytes [A0, 69, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076da1380 8 bytes {JMP QWORD [RIP-0x4d4cf]}
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076da1500 8 bytes {JMP QWORD [RIP-0x4d498]}
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076da1530 8 bytes {JMP QWORD [RIP-0x4d9b1]}
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076da1650 8 bytes {JMP QWORD [RIP-0x4d7a7]}
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076da1700 8 bytes {JMP QWORD [RIP-0x4d9e3]}
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076da1d30 8 bytes {JMP QWORD [RIP-0x4dba6]}
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076da1f80 8 bytes {JMP QWORD [RIP-0x4de55]}
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076da27e0 8 bytes {JMP QWORD [RIP-0x4e770]}
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000747e13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000747e146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000747e16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessTerm + 3 00000000747e16e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000747e19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000747e19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetInstructionPointer + 23 00000000747e1a1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuNotifyAffinityChange + 3 00000000747e1a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000747e1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessDebugEvent + 3 00000000747e1a6f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\syswow64\KERNELBASE.dll!HeapCreate 0000000075c2549c 5 bytes JMP 00000001003d0800
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000076f01465 2 bytes [F0, 76]
.text C:\Program Files (x86)\Common Files\Steam\SteamService.exe[5088] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000076f014bb 2 bytes [F0, 76]
.text ... * 2
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 5 0000000076d511f5 8 bytes {JMP 0xd}
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 416 0000000076d51390 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076d5143f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 492 0000000076d5158c 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076d5191e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 636 0000000076d51b1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 204 0000000076d51bf0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076d51d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 691 0000000076d51eb3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076d51edf 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!_ui64toa + 84 0000000076d51f64 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 81 0000000076d51fbd 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelf + 7 0000000076d51fd7 8 bytes {JMP 0xb}
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 658 0000000076d52272 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 801 0000000076d52301 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlInstallFunctionTableCallback + 578 0000000076d52792 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076d527b0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076d527d2 8 bytes {JMP 0x10}
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076d5282f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 176 0000000076d52890 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076d52d1b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 367 0000000076d52d5f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlCutoverTimeToSystemTime + 483 0000000076d53023 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076d5323b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 912 0000000076d533c0 16 bytes {JMP 0x4e}
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076d53a5e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076d53ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076d53b85 8 bytes [10, 6A, F8, 7E, 00, 00, 00, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 611 0000000076d53d23 8 bytes [00, 6A, F8, 7E, 00, 00, 00, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076d54190 8 bytes [A0, 69, F8, 7E, 00, 00, 00, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076da1380 8 bytes {JMP QWORD [RIP-0x4d4cf]}
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076da1500 8 bytes {JMP QWORD [RIP-0x4d498]}
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076da1530 8 bytes {JMP QWORD [RIP-0x4d9b1]}
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076da1650 8 bytes {JMP QWORD [RIP-0x4d7a7]}
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076da1700 8 bytes {JMP QWORD [RIP-0x4d9e3]}
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076da1d30 8 bytes {JMP QWORD [RIP-0x4dba6]}
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076da1f80 8 bytes {JMP QWORD [RIP-0x4de55]}
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076da27e0 8 bytes {JMP QWORD [RIP-0x4e770]}
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000747e13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000747e146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000747e16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessTerm + 3 00000000747e16e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000747e19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000747e19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetInstructionPointer + 23 00000000747e1a1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuNotifyAffinityChange + 3 00000000747e1a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000747e1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessDebugEvent + 3 00000000747e1a6f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\user32.DLL!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\user32.DLL!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\user32.DLL!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076f01465 2 bytes [F0, 76]
.text C:\ProgramData\Battle.net\Agent\Agent.2328\Agent.exe[6152] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076f014bb 2 bytes [F0, 76]
.text ... * 2
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 5 0000000076d511f5 8 bytes {JMP 0xd}
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 416 0000000076d51390 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000076d5143f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 492 0000000076d5158c 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000076d5191e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 636 0000000076d51b1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 204 0000000076d51bf0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000076d51d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 691 0000000076d51eb3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000076d51edf 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!_ui64toa + 84 0000000076d51f64 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 81 0000000076d51fbd 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelf + 7 0000000076d51fd7 8 bytes {JMP 0xb}
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 658 0000000076d52272 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 801 0000000076d52301 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlInstallFunctionTableCallback + 578 0000000076d52792 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000076d527b0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000076d527d2 8 bytes {JMP 0x10}
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000076d5282f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 176 0000000076d52890 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 2
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000076d52d1b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 367 0000000076d52d5f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text ... * 3
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlCutoverTimeToSystemTime + 483 0000000076d53023 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000076d5323b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 912 0000000076d533c0 16 bytes {JMP 0x4e}
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000076d53a5e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000076d53ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000076d53b85 8 bytes [10, 6A, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 611 0000000076d53d23 8 bytes [00, 6A, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000076d54190 8 bytes [A0, 69, F8, 7E, 00, 00, 00, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000076da1380 8 bytes {JMP QWORD [RIP-0x4d4cf]}
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000076da1500 8 bytes {JMP QWORD [RIP-0x4d498]}
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000076da1530 8 bytes {JMP QWORD [RIP-0x4d9b1]}
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000076da1650 8 bytes {JMP QWORD [RIP-0x4d7a7]}
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000076da1700 8 bytes {JMP QWORD [RIP-0x4d9e3]}
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000076da1d30 8 bytes {JMP QWORD [RIP-0x4dba6]}
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000076da1f80 8 bytes {JMP QWORD [RIP-0x4de55]}
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000076da27e0 8 bytes {JMP QWORD [RIP-0x4e770]}
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000747e13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000747e146b 8 bytes {JMP 0xffffffffffffffb0}
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000747e16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessTerm + 3 00000000747e16e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000747e19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000747e19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetInstructionPointer + 23 00000000747e1a1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuNotifyAffinityChange + 3 00000000747e1a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000747e1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessDebugEvent + 3 00000000747e1a6f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!RegQueryValueExW 00000000765d1eee 7 bytes JMP 00000001703c16b3
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!RegSetValueExW 00000000765d5b85 7 bytes JMP 00000001703c11cc
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!RegSetValueExA 00000000765e13e1 7 bytes JMP 00000001703c12a8
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!RegDeleteValueW 00000000765eea0d 7 bytes JMP 00000001703c1262
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!K32GetModuleFileNameExW 00000000765fb1d3 5 bytes JMP 00000001703c15c8
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!K32EnumProcessModulesEx 00000000766788b4 7 bytes JMP 00000001703c1357
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!K32GetModuleInformation 0000000076678939 5 bytes JMP 00000001703c16f4
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\kernel32.dll!K32GetMappedFileNameW 0000000076678c8f 5 bytes JMP 00000001703c101e
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleW 0000000075c21d1b 5 bytes JMP 00000001703c11e5
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\KERNELBASE.dll!GetModuleHandleExW 0000000075c21dc9 5 bytes JMP 00000001703c1019
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW 0000000075c22aa4 5 bytes JMP 00000001703c1573
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\KERNELBASE.dll!FreeLibrary 0000000075c22d0a 5 bytes JMP 00000001703c128f
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\USER32.dll!CreateWindowExW 0000000075ae8a29 5 bytes JMP 00000001703c1046
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesA 0000000075af4572 5 bytes JMP 00000001703c10c8
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW 0000000075b0e567 3 bytes JMP 00000001703c1433
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\USER32.dll!EnumDisplayDevicesW + 4 0000000075b0e56b 1 byte [FA]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\USER32.dll!DisplayConfigGetDeviceInfo 0000000075b47a5c 5 bytes JMP 00000001703c15f0
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\GDI32.dll!D3DKMTGetDisplayModeList 000000007586e9a2 5 bytes JMP 00000001703c15e1
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\GDI32.dll!D3DKMTQueryAdapterInfo 000000007586ebdc 5 bytes JMP 00000001703c11a9
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076f01465 2 bytes [F0, 76]
.text C:\Program Files (x86)\Battle.net\Battle.net.3823\Battle.net.exe[6312] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076f014bb 2 bytes [F0, 76]
.text ... * 2 |