intradeep | 20.03.2015 19:06 | GMER Logfile: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-03-20 17:59:08
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000003f TOSHIBA_MK5061GSY rev.MC102E 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\SVENS_~1\AppData\Local\Temp\kwkiqfow.sys
---- Kernel code sections - GMER 2.1 ----
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000116e00 7 bytes [00, 3C, 7F, 01, 00, FA, F1]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff96000116e08 7 bytes [01, 22, C0, FF, 00, D7, DA]
---- User code sections - GMER 2.1 ----
.text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f91b02177a 4 bytes [02, 1B, F9, 07]
.text C:\Windows\System32\spoolsv.exe[2036] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f91b021782 4 bytes [02, 1B, F9, 07]
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\Windows\system32\dwm.exe[2076] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 000007f91c552100 5 bytes JMP 000007fa1a220500
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 000007f91c565d4c 7 bytes JMP 000007fa1a220538
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f916861532 4 bytes [86, 16, F9, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f91686153a 4 bytes [86, 16, F9, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[2096] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f91686165a 4 bytes [86, 16, F9, 07]
.text C:\Windows\system32\nvvsvc.exe[2104] C:\Windows\system32\MSIMG32.dll!GradientFill + 690 000007f916861532 4 bytes [86, 16, F9, 07]
.text C:\Windows\system32\nvvsvc.exe[2104] C:\Windows\system32\MSIMG32.dll!GradientFill + 698 000007f91686153a 4 bytes [86, 16, F9, 07]
.text C:\Windows\system32\nvvsvc.exe[2104] C:\Windows\system32\MSIMG32.dll!TransparentBlt + 246 000007f91686165a 4 bytes [86, 16, F9, 07]
.text C:\Windows\system32\nvvsvc.exe[2104] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f91b02177a 4 bytes [02, 1B, F9, 07]
.text C:\Windows\system32\nvvsvc.exe[2104] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f91b021782 4 bytes [02, 1B, F9, 07]
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 000007f91c552100 5 bytes JMP 000007fa1a220500
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 000007f91c565d4c 7 bytes JMP 000007fa1a220538
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f91b02177a 4 bytes [02, 1B, F9, 07]
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f91b021782 4 bytes [02, 1B, F9, 07]
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f916861532 4 bytes [86, 16, F9, 07]
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f91686153a 4 bytes [86, 16, F9, 07]
.text C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe[2276] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f91686165a 4 bytes [86, 16, F9, 07]
.text C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe[2636] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f91b02177a 4 bytes [02, 1B, F9, 07]
.text C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe[2636] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f91b021782 4 bytes [02, 1B, F9, 07]
.text C:\Program Files\Windows Defender\MsMpEng.exe[2552] C:\Windows\system32\psapi.dll!GetProcessImageFileNameA + 306 000007f91b02177a 4 bytes [02, 1B, F9, 07]
.text C:\Program Files\Windows Defender\MsMpEng.exe[2552] C:\Windows\system32\psapi.dll!GetProcessImageFileNameA + 314 000007f91b021782 4 bytes [02, 1B, F9, 07]
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\SYSTEM32\user32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\SYSTEM32\user32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\SYSTEM32\user32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\SYSTEM32\user32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\SYSTEM32\user32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\Windows\system32\taskhostex.exe[4524] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a200340
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a200298
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a200260
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2002d0
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a200228
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2001f0
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a200308
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2000d8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a200180
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a200110
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a200148
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2001b8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a200420
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a200378
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2003b0
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2003e8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a200458
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2004c8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a200490
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\SYSTEM32\d3d9.dll!Direct3DCreate9Ex 000007f90d89ada0 5 bytes JMP 000007f91a2005a8
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\SYSTEM32\d3d9.dll!Direct3DCreate9 000007f90d8bd6c8 6 bytes JMP 000007f91a200570
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 000007f91c552100 5 bytes JMP 000007fa1a200500
.text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[4676] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 000007f91c565d4c 7 bytes JMP 000007fa1a200538
.text C:\Windows\Explorer.EXE[4992] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f916861532 4 bytes [86, 16, F9, 07]
.text C:\Windows\Explorer.EXE[4992] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f91686153a 4 bytes [86, 16, F9, 07]
.text C:\Windows\Explorer.EXE[4992] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f91686165a 4 bytes [86, 16, F9, 07]
.text C:\Windows\Explorer.EXE[4992] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f91b02177a 4 bytes [02, 1B, F9, 07]
.text C:\Windows\Explorer.EXE[4992] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f91b021782 4 bytes [02, 1B, F9, 07]
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 000007f91c552100 5 bytes JMP 000007fa1a220500
.text C:\Windows\system32\igfxEM.exe[3312] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 000007f91c565d4c 7 bytes JMP 000007fa1a220538
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 000007f91c552100 5 bytes JMP 000007fa1a220500
.text C:\Windows\system32\igfxHK.exe[4340] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 000007f91c565d4c 7 bytes JMP 000007fa1a220538
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a200340
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a200298
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a200260
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2002d0
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a200228
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2001f0
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a200308
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2000d8
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a200180
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a200110
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a200148
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2001b8
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a200420
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a200378
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2003b0
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2003e8
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a200458
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2004c8
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a200490
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 000007f91c552100 5 bytes JMP 000007fa1a200500
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 000007f91c565d4c 7 bytes JMP 000007fa1a200538
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f916861532 4 bytes [86, 16, F9, 07]
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f91686153a 4 bytes [86, 16, F9, 07]
.text C:\Program Files\Classic Shell\ClassicStartMenu.exe[4444] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f91686165a 4 bytes [86, 16, F9, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a200340
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a200298
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a200260
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2002d0
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a200228
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2001f0
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a200308
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2000d8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a200180
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a200110
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a200148
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2001b8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a200420
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a200378
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2003b0
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2003e8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a200458
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2004c8
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a200490
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f916861532 4 bytes [86, 16, F9, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f91686153a 4 bytes [86, 16, F9, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f91686165a 4 bytes [86, 16, F9, 07]
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 000007f91c552100 5 bytes JMP 000007fa1a200500
.text C:\Program Files\NVIDIA Corporation\Display\nvtray.exe[2248] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 000007f91c565d4c 7 bytes JMP 000007fa1a200538
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f91b02177a 4 bytes [02, 1B, F9, 07]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f91b021782 4 bytes [02, 1B, F9, 07]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 000007f91c552100 5 bytes JMP 000007fa1a220500
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[6308] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 000007f91c565d4c 7 bytes JMP 000007fa1a220538
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 000007f91c552100 5 bytes JMP 000007fa1a220500
.text C:\Program Files\Synaptics\SynTP\SynTPLpr.exe[6448] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 000007f91c565d4c 7 bytes JMP 000007fa1a220538
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f91b02177a 4 bytes [02, 1B, F9, 07]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f91b021782 4 bytes [02, 1B, F9, 07]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[6544] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 000007f91c552100 5 bytes JMP 000007fa1a220500
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 000007f91c565d4c 7 bytes JMP 000007fa1a220538
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\psapi.dll!GetProcessImageFileNameA + 306 000007f91b02177a 4 bytes [02, 1B, F9, 07]
.text C:\Program Files\Logitech Gaming Software\LCore.exe[6732] C:\Windows\system32\psapi.dll!GetProcessImageFileNameA + 314 000007f91b021782 4 bytes [02, 1B, F9, 07]
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f916861532 4 bytes [86, 16, F9, 07]
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f91686153a 4 bytes [86, 16, F9, 07]
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f91686165a 4 bytes [86, 16, F9, 07]
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 000007f91c552100 5 bytes JMP 000007fa1a220500
.text C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe[6768] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 000007f91c565d4c 7 bytes JMP 000007fa1a220538
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\KERNEL32.dll!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\Program Files (x86)\Lenovo\Energy Management\utility.exe[6892] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\SYSTEM32\WSOCK32.dll!recvfrom + 742 000007f90a3d1b32 4 bytes [3D, 0A, F9, 07]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\SYSTEM32\WSOCK32.dll!recvfrom + 750 000007f90a3d1b3a 4 bytes [3D, 0A, F9, 07]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f91b02177a 4 bytes [02, 1B, F9, 07]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f91b021782 4 bytes [02, 1B, F9, 07]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f916861532 4 bytes [86, 16, F9, 07]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f91686153a 4 bytes [86, 16, F9, 07]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f91686165a 4 bytes [86, 16, F9, 07]
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 000007f91c552100 5 bytes JMP 000007fa1a220500
.text C:\Program Files\Logitech\SetPointP\SetPoint.exe[6024] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 000007f91c565d4c 7 bytes JMP 000007fa1a220538
.text C:\Windows\System32\rundll32.exe[6204] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f916861532 4 bytes [86, 16, F9, 07]
.text C:\Windows\System32\rundll32.exe[6204] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f91686153a 4 bytes [86, 16, F9, 07]
.text C:\Windows\System32\rundll32.exe[6204] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f91686165a 4 bytes [86, 16, F9, 07]
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[4776] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
.text C:\Windows\system32\rundll32.exe[964] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 690 000007f916861532 4 bytes [86, 16, F9, 07]
.text C:\Windows\system32\rundll32.exe[964] C:\Windows\SYSTEM32\MSIMG32.dll!GradientFill + 698 000007f91686153a 4 bytes [86, 16, F9, 07]
.text C:\Windows\system32\rundll32.exe[964] C:\Windows\SYSTEM32\MSIMG32.dll!TransparentBlt + 246 000007f91686165a 4 bytes [86, 16, F9, 07]
.text C:\Windows\system32\rundll32.exe[964] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 306 000007f91b02177a 4 bytes [02, 1B, F9, 07]
.text C:\Windows\system32\rundll32.exe[964] C:\Windows\system32\PSAPI.DLL!GetProcessImageFileNameA + 314 000007f91b021782 4 bytes [02, 1B, F9, 07]
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 000007f91cdb259c 8 bytes JMP 000007fa1a220340
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 000007f91cdb6b00 9 bytes JMP 000007fa1a220298
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 000007f91ce35908 7 bytes JMP 000007fa1a220260
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 000007f91ce51610 7 bytes JMP 000007fa1a2202d0
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 000007f91ce649a4 7 bytes JMP 000007fa1a220228
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 000007f91ce64a38 8 bytes JMP 000007fa1a2201f0
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 000007f91ce65074 8 bytes JMP 000007fa1a220308
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 000007f91a2b1f70 7 bytes JMP 000007fa1a2200d8
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 000007f91a2b1ff0 5 bytes JMP 000007fa1a220180
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 000007f91a2b5880 5 bytes JMP 000007fa1a220110
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007f91a2b8650 6 bytes JMP 000007fa1a220148
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 000007f91a2e0510 5 bytes JMP 000007fa1a2201b8
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\USER32.dll!CreateWindowExW 000007f91c3fa0d0 7 bytes JMP 000007fa1a220420
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 000007f91c40e240 9 bytes JMP 000007fa1a220378
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 000007f91c40eda0 5 bytes JMP 000007fa1a2203b0
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 000007f91c40f2e0 5 bytes JMP 000007fa1a2203e8
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 000007f91c40f5b0 5 bytes JMP 000007fa1a220458
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 000007f91cab1070 8 bytes JMP 000007fa1a2204c8
.text C:\Windows\WinStore\WSHost.exe[8080] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 000007f91cad0b70 8 bytes JMP 000007fa1a220490
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [1380:7348] fffff960008245e8
---- EOF - GMER 2.1 ---- --- --- ---
ESET online scanner log: Code:
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=cd6fb58c118b084fb9da5619d77cb018
# engine=22992
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-03-20 12:27:20
# local_time=2015-03-20 01:27:20 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 12462 4324770 0 0
# scanned=67461
# found=2
# cleaned=0
# scan_time=2683
sh=EAE2784C9115FE9CFA44A116B74E72C1BCCFA7F6 ft=1 fh=2e79e77116fe19c4 vn="Win32/DownWare.L evtl. unerwünschte Anwendung" ac=I fn="C:\Downloads\MyPhoneExplorer_Setup_1.8.5.exe"
sh=1447092BA29779C726829611180994E17718C412 ft=1 fh=23f22b72eb3a5b90 vn="Win32/InstallMonetizer.AQ evtl. unerwünschte Anwendung" ac=I fn="C:\Downloads\PDFCreator-1_7_2_setup_offline.exe" MBAB: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 20.03.2015
Scan Time: 18:30:59
Logfile: mbaw-log.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.03.14.02
Rootkit Database: v2015.02.25.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8
CPU: x64
File System: NTFS
User: svens_000
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 348839
Time Elapsed: 18 min, 7 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 1
PUP.Optional.PutLocker.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\koalekbhpbggkcfhkkbolikjoaobbppi, , [f377fd4846442016ad09cced5ea59070],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end) Könnt Ihr mir weiterhelfen? Ich bin ratlos! Vielen Dank! |