
UNSOLVED
Redirected search
When I tried to do a google search, I have been redirected to a different page. This occur only sometimes and when this happens, another unwanted window also opens up. Can someone please look into this log file and help me fix these errors. Thanks.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:34:26 AM, on 6/25/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\RegGenie\RegGenieScheduler.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Fingerprint Reader Suite\psqltray.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\1-Click Answers\answers.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Dell Remote Access\ezi_ra.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\PROGRA~1\1-CLIC~1\agtserv.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: IndianTerminalLive Toolbar - {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - C:\Program Files\IndianTerminalLive\tbIndi.dll
R3 - URLSearchHook: (no name) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IndianTerminalLive Toolbar - {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - C:\Program Files\IndianTerminalLive\tbIndi.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: IndianTerminalLive Toolbar - {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - C:\Program Files\IndianTerminalLive\tbIndi.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\coIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Fingerprint Reader Suite\launcher.exe" /startup
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\RunOnce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq
O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\Windows\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
O4 - HKCU\..\Run: [googletalk] C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Jumblo] "C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe" -nosplash -minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Dell Remote Access.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: Answers... - file://C:\Program Files\1-Click Answers\Html\atiemenu.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.4.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://mdev.temple.edu/webcams/AxisCamControl.ocx
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Advanced Networking Service (hnmsvc) - Dell Inc. - c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
--
End of file - 14853 bytes
Responses (46)
Solutions (0)
Hello K27,
Thank you for helping me out. When I tried to run another system scan and save a copy of the log file, I got a dialog box as follows:
For some reason yoursystem denied write access to the Hosts file. If any hijacked domains are in this file, HiJackThis may not be able to fix this..........
After I clicked ok, I got the log file shown below:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:34:26 AM, on 6/25/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: NormalRunning processes:
C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\RegGenie\RegGenieScheduler.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Fingerprint Reader Suite\psqltray.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\1-Click Answers\answers.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Dell Remote Access\ezi_ra.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\PROGRA~1\1-CLIC~1\agtserv.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: IndianTerminalLive Toolbar - {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - C:\Program Files\IndianTerminalLive\tbIndi.dll
R3 - URLSearchHook: (no name) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IndianTerminalLive Toolbar - {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - C:\Program Files\IndianTerminalLive\tbIndi.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: IndianTerminalLive Toolbar - {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - C:\Program Files\IndianTerminalLive\tbIndi.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\coIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Fingerprint Reader Suite\launcher.exe" /startup
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\RunOnce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq
O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\Windows\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
O4 - HKCU\..\Run: [googletalk] C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Jumblo] "C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe" -nosplash -minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Dell Remote Access.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: Answers... - file://C:\Program Files\1-Click Answers\Html\atiemenu.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.4.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://mdev.temple.edu/webcams/AxisCamControl.ocx
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Advanced Networking Service (hnmsvc) - Dell Inc. - c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe--
End of file - 14853 bytesSymptoms: Redirected searches, a new problem popped up in the past days. My disk crashes occasionally (a blue screen appears and then shut down the computer). More often, IE displays as not responding . Hope this will help. Thanks.
Reply kevin27_b3d29f
2 Intern
•
1547 Posts
425
0
Posted July 13th, 2010 14:00
Hi lutts,
Your Welcome. And the symptoms you described were a great help, Thank You.
The message from HJT is because you are running Vista and as such you need to right click the program and then click Run as Administrator. Please also do this for all other programs I ask you to run, it will make things go a bit more smoothly.
Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.
Please Print or Save to Notepad all instructions and please follow them carefully and if there's something you don't understand or that will not work please let me know and we will go through it together.
Please DO NOT use this system for anything apart from visiting this forum and other sites I direct you too, as this will only make the cleanup process all the more diffecult.
I need to see some additional information about what is happening in your machine.
Please perform the following scan:- Download DDS by sUBs from one of the following links. Save it to your desktop.
- Double click on the DDS icon, allow it to run.
- A small box will open, with an explanation about the tool.
- When done, DDS will open two (2) logs
1. DDS.txt
2. Attach.txt - Save both reports to your desktop.
- The instructions here ask you to attach the Attach.txt.
- Instead of attaching, please copy/past both logs into your next reply.
- Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control hereYOU MUST DISABLE ALL REAL TIME PROTECTION BEFORE RUNNING THE NEXT TOOL,
Next, download this Antirootkit Program to a folder that you create such as C:\ARK, by choosing the "Download EXE" button on the webpage.
Please Disable all Anti-virus/Anti-Spyware/FireWall on your machine(instructions via links below)
Next, please perform a rootkit scan:
- Double-click the randomly name EXE located in the C:\ARK folder that you just downloaded to launch it
- When the program opens, it will automatically initiate a very fast scan of common rootkit hiding places.
- When the "quick" scan is finished (a few seconds), click the Rootkit/Malware tab,and then select the Scan button.
- Leave your system completely idle while this longer scan is in progress.
- When the scan is done, save the scan log to the Windows clipboard
- Open Notepad or a similar text editor
- Paste the clipboard contents into a text file by clicking Edit | Paste or Ctl V
- Exit the Program
- Save the Scan log as ARK.txt and post it in your next reply.
- Now, re-enable the active protection component of any antivirus/antimalware programs you disabled before performing the scan.
.
If the ARK tool crashes your machine or causes a Blue Screen error, please post the log results from the first inital quick scan,this can be saved in the same way as the full scan in the above instructions.Please COPY/PASTE BOTH DDS logs and the ARK log back to this thread,
Thanks
K27Reply kevin27_b3d29f
2 Intern
•
1547 Posts
425
0
Posted July 15th, 2010 11:00
Hi lutts,
Do you still require assistance?
Thanks.
Reply Hi K27,
I really need your assistance. What happenned was, all this time I was expecting an e-mail from you but now only I realizedI I kinda overlooked your e-mail. My inbox is full of unwanted mails and your e-mail was buried in it. I am very sorry for the inconvenience. I was going to my usual websites as I didn`t read the instructions in ur e-mail. Do you want me to send a new HJT log? I will post a new HJT log and post the other required things mentioned in your previous e-mail soon. Sorry again for my late reply.
Thanks,
lutts
Reply kevin27_b3d29f
2 Intern
•
1547 Posts
425
0
Posted July 15th, 2010 22:00
Hi lutts,
Don't worry about the email thing, there seems to have been some sort of problem with it over the last few day's but I think it is getting better.
There is no need to post a fresh HJT log yet. Please follow the instruction's in my last post for running DDS and the ARK tool.
thanks,
K27.Reply Hey K27,
I forgot to mention some symptoms in my earlier posts: I often get a message showing that Windows Host Services stopped working and the norton warns an intrusion attack and was resulted from DEVICE/HARDDISKVOLUME3/PROGRAMFILES/INTERNETEXPLORER/EXPLORER.EXE. Orsometime its shows the attack was resulted from SYSTEM32/SVCHOST.EXE something like that...
Here is the DDS LOG:
DDS (Ver_10-03-17.01) - NTFSx86
Run by APARNA at 12:21:20.25 on Fri 07/16/2010
Internet Explorer: 7.0.6002.18005
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3069.1061 [GMT -4:00]SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Fingerprint Reader Suite\upeksvr.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\aestsrv.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\1-Click Answers\answers.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell Remote Access\ezi_ra.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Fingerprint Reader Suite\psqltray.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\1-CLIC~1\agtserv.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Users\APARNA\Downloads\dds.pif============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uStart Page = www.yahoo.com
uWindow Title = Internet Explorer provided by Dell
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6090117
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
uURLSearchHooks: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
uURLSearchHooks: H - No File
mURLSearchHooks: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\norton 360\engine\4.2.0.12\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\norton 360\engine\4.2.0.12\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\norton 360\engine\4.2.0.12\coIEPlg.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [googletalk] c:\users\aparna\appdata\roaming\google\google talk\googletalk.exe /autostart
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Jumblo] "c:\program files\jumblo.com\jumblo\Jumblo.exe" -nosplash -minimized
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [PSQLLauncher] "c:\program files\fingerprint reader suite\launcher.exe" /startup
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [Dell DataSafe Online] "c:\program files\dell datasafe online\DataSafeOnline.exe" /m
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRunOnce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq
mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
mRunOnce: [VistaSetup]
mRunOnce: [*Restore] c:\windows\system32\rstrui.exe /runonce
StartupFolder: c:\users\aparna\appdata\roaming\micros~1\windows\startm~1\programs\startup\delldo~1.lnk - c:\program files\dell\delldock\DellDock.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\1-clic~1.lnk - c:\program files\1-click answers\answers.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dellre~1.lnk - c:\windows\installer\{f66a31d9-7831-4fba-ba02-c411c0047cc5}\NewShortcut10_F66A31D978314FBABA02C411C0047CC5.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: DisableCAD = 1 (0x1)
IE: Answers... - file://c:\program files\1-click answers\html\atiemenu.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.4.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://mdev.temple.edu/webcams/AxisCamControl.ocx
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: psfus - c:\windows\system32\psqlpwd.dll
AppInit_DLLs: c:\progra~1\google\google~3\GOEC62~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli psqlpwd
Hosts: 127.0.0.1 www.spywareinfo.com============= SERVICES / DRIVERS ===============
R0 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2010-7-5 42376]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0402000.00c\symds.sys [2010-6-11 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0402000.00c\symefa.sys [2010-6-11 173104]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\bashdefs\20100709.001\BHDrvx86.sys [2010-7-12 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0402000.00c\cchpx86.sys [2010-6-11 501888]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\ipsdefs\20100715.001\IDSvix86.sys [2010-7-16 344112]
R1 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2010-7-5 66952]
R1 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2010-7-5 81288]
R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2010-7-5 160648]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0402000.00c\ironx86.sys [2010-6-11 116784]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0402000.00c\symtdiv.sys [2010-6-11 339504]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2009-1-17 73728]
R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-9-24 155648]
R2 N360;Norton 360;c:\program files\norton 360\norton 360\engine\4.2.0.12\ccsvchst.exe [2010-6-11 126392]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-6-11 1153368]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-7-5 356920]
R2 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2010-7-5 1073544]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-7-5 102448]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-19 135664]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-2-15 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-1-17 30192]
S4 iaNvStor;Intel(R) Turbo Memory Controller;c:\windows\system32\drivers\iaNvStor.sys [2009-1-17 209408]=============== Created Last 30 ================
2010-07-14 23:15:34 0 d-----w- c:\windows\system32\Adobe
2010-07-05 23:10:23 1905 ----a-w- c:\windows\diagwrn.xml
2010-07-05 23:10:23 1905 ----a-w- c:\windows\diagerr.xml
2010-07-05 20:06:00 160648 ----a-w- c:\windows\system32\drivers\pctfw2.sys
2010-07-05 20:05:52 29576 ----a-w- c:\windows\system32\drivers\kcom.sys
2010-07-05 20:05:51 81288 ----a-w- c:\windows\system32\drivers\iksyssec.sys
2010-07-05 20:05:51 66952 ----a-w- c:\windows\system32\drivers\iksysflt.sys
2010-07-05 20:05:51 42376 ----a-w- c:\windows\system32\drivers\ikfilesec.sys
2010-07-05 20:05:33 0 d-----w- c:\users\aparna\appdata\roaming\PC Tools
2010-07-05 20:05:33 0 d-----w- c:\programdata\PC Tools
2010-07-05 19:13:33 767952 ----a-w- c:\windows\BDTSupport.dll.old
2010-07-05 19:13:32 1652688 ----a-w- c:\windows\PCTBDCore.dll.old
2010-07-05 19:09:53 0 d-----w- c:\program files\Spyware Doctor
2010-07-05 19:09:53 0 d-----w- c:\program files\common files\PC Tools
2010-06-25 15:33:50 0 d-----w- c:\program files\Trend Micro
2010-06-18 20:51:01 0 d-----w- c:\programdata\HP Product Assistant==================== Find3M ====================
2010-07-16 13:58:56 48158 ----a-w- c:\programdata\nvModes.dat
2010-06-18 20:54:25 51200 ----a-w- c:\windows\inf\infpub.dat
2010-06-18 20:54:25 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-06-18 20:54:25 143360 ----a-w- c:\windows\inf\infstor.dat
2010-06-11 16:24:01 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-06-11 16:24:01 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-06-11 16:24:01 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-06-11 16:20:40 145503112 ----a-w- c:\users\aparna\N360_2010_4.0_Build_127_OEM90_Microsoft.exe
2010-05-21 18:14:28 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-02 13:42:25 8656832 ----a-w- c:\users\aparna\appdata\roaming\DataSafeDotNet.exe
2010-04-28 07:00:59 67424 ----a-w- c:\windows\fonts\upcfi.ttf
2010-04-23 14:13:55 2048 ----a-w- c:\windows\system32\tzres.dll
2010-02-15 19:34:56 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-01-17 21:02:56 75 --sha-r- c:\windows\CT4CET.bin
2009-01-17 22:17:13 8192 --sha-w- c:\windows\users\default\NTUSER.DAT============= FINISH: 12:23:14.56 ===============
Here is the ARK log:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-16 14:19:10
Windows 6.0.6002 Service Pack 2
Running: qb58ektc.exe; Driver: C:\Users\APARNA\AppData\Local\Temp\pwryqpob.sys
---- System - GMER 1.0.15 ----SSDT 92BF6120 ZwAlertResumeThread
SSDT 92BF5120 ZwAlertThread
SSDT 933D5940 ZwAllocateVirtualMemory
SSDT 913F8C98 ZwAlpcConnectPort
SSDT 92F70048 ZwAssignProcessToJobObject
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateKey [0x8FB1B7A6]
SSDT 933DEFC0 ZwCreateMutant
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcess [0x8FB18794]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcessEx [0x8FB18F1E]
SSDT 933E37B8 ZwCreateSymbolicLinkObject
SSDT 933D7380 ZwCreateThread
SSDT 92FBE048 ZwDebugActiveProcess
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwDeleteKey [0x8FB1C1F0]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwDeleteValueKey [0x8FB1C42A]
SSDT 933D5B58 ZwDuplicateObject
SSDT 933D7B30 ZwFreeVirtualMemory
SSDT 92F93048 ZwImpersonateAnonymousToken
SSDT 92F74048 ZwImpersonateThread
SSDT 89C9F728 ZwLoadDriver
SSDT 933D79D0 ZwMapViewOfSection
SSDT 92F94048 ZwOpenEvent
SSDT 933D5DB8 ZwOpenProcess
SSDT 9182A118 ZwOpenProcessToken
SSDT 92FA9048 ZwOpenSection
SSDT 933D5CA8 ZwOpenThread
SSDT 933E13F0 ZwProtectVirtualMemory
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwRenameKey [0x8FB1D12A]
SSDT 9190F120 ZwResumeThread
SSDT 91909108 ZwSetContextThread
SSDT 933D77B8 ZwSetInformationProcess
SSDT 92FBD048 ZwSetSystemInformation
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwSetValueKey [0x8FB1C83C]
SSDT 92FA8048 ZwSuspendProcess
SSDT 901F7120 ZwSuspendThread
SSDT 91825108 ZwTerminateProcess
SSDT 901F5118 ZwTerminateThread
SSDT 91904118 ZwUnmapViewOfSection
SSDT 933D7E40 ZwWriteVirtualMemory
SSDT 933E2FB0 ZwCreateThreadEx
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateUserProcess [0x8FB196B6]---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 11D 81CED880 8 Bytes [20, 61, BF, 92, 20, 51, BF, ...] {AND [ECX-0x41], AH; XCHG EDX, EAX; AND [ECX-0x41], DL; XCHG EDX, EAX}
.text ntkrnlpa.exe!KeSetEvent + 131 81CED894 4 Bytes [40, 59, 3D, 93]
.text ntkrnlpa.exe!KeSetEvent + 13D 81CED8A0 4 Bytes [98, 8C, 3F, 91]
.text ntkrnlpa.exe!KeSetEvent + 191 81CED8F4 4 Bytes [48, 00, F7, 92] {DEC EAX; ADD BH, DH; XCHG EDX, EAX}
.text ntkrnlpa.exe!KeSetEvent + 1E9 81CED94C 4 Bytes [A6, B7, B1, 8F]
.text ...
? C:\Windows\system32\Drivers\mchInjDrv.sys The system cannot find the file specified. !---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\Dwm.exe[172] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[600] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\wininit.exe[652] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\lsm.exe[720] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[880] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[1004] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\winlogon.exe[1092] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[1124] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 0028000A
.text C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 0029000A
.text C:\Windows\system32\svchost.exe[1148] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0027000A
.text C:\Windows\system32\svchost.exe[1148] ole32.dll!CoCreateInstance 76709EA6 5 Bytes JMP 007C000A
.text C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Windows\system32\svchost.exe[1148] USER32.dll!GetCursorPos 77B60B88 5 Bytes JMP 012E000A
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1500] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1680] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1984] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\taskeng.exe[2500] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[2612] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\Explorer.EXE[2740] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 0083000A
.text C:\Windows\Explorer.EXE[2740] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 0084000A
.text C:\Windows\Explorer.EXE[2740] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0082000A
.text C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\DllHost.exe[2756] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[2792] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] kernel32.dll!CreateThread + 1A 7661C928 4 Bytes CALL 0044A801 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\STacSV.exe[3244] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[3312] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[3352] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\taskeng.exe[3568] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 0023000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 0024000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0022000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamW 77B710B0 5 Bytes JMP 6BE7BF9F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamW 77B72EF5 5 Bytes JMP 6BFBB45A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamA 77B88152 5 Bytes JMP 6BFBB41F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamA 77B8847D 5 Bytes JMP 6BFBB495 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectA 77B9D4D9 5 Bytes JMP 6BFBB3DB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectW 77B9D5D3 5 Bytes JMP 6BFBB397 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExA 77B9D639 5 Bytes JMP 6BFBB35D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExW 77B9D65D 5 Bytes JMP 6BFBB323 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D1D 76F88910 4 Bytes [99, 0B, BE, 63]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D25 76F88918 4 Bytes [A7, 0A, BE, 63]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D95 76F88988 4 Bytes [99, 0B, BE, 63]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D9D 76F88990 8 Bytes [A7, 0A, BE, 63, A4, 32, BD, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ole32.dll!OleLoadFromStream 766D1E12 5 Bytes JMP 6BFBB657 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\OEM02Mon.exe[4564] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\rundll32.exe[4816] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!CreateThread + 1A 7661C928 4 Bytes CALL 0044A815 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F0A0F5A
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 006A000A
.text C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 006B000A
.text C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0069000A
.text C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[5456] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A---- User IAT/EAT - GMER 1.0.15 ----
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcessHeap] 00C0E660
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] 00C0E140
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DuplicateHandle] 00C0D2A0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!IsDebuggerPresent] 00C0EBE0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateThread] 00C0C260
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 00C0BBD0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetEnvironmentStringsW] 00C0BF90
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetFilePointer] 00C0D100
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFileEx] 00C0D7C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileMappingW] 00C0D550
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFile] 00C0D740
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!OpenFileMappingW] 00C0DC20
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!UnmapViewOfFile] 00C0D930
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileType] 00C0D450
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FlushViewOfFile] 00C0D690
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileSize] 00C0D240
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!WriteFile] 00C0D0C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetACP] 00C0E680
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!TerminateProcess] 00C0C110
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalAlloc] 00C0E3A0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalLock] 00C0E2C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalUnlock] 00C0E280
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] 00C0C940
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 00C0BA30
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CloseHandle] 00C0D340
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 00C0B9A0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 00C0BC80
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 00C0A730
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!ReadFile] 00C0CC90
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetVersion] 00C0E650
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadIconW] 00C0E920
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadCursorW] 00C0E8C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!CreateDialogParamW] 00C0EB10
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!DialogBoxParamW] 00C0EBB0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadStringW] 00C0E9E0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] 00C0E5D0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] 00C0E580
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [752C7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [7531A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [752CBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [752BF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [752C75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [752BE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [752F8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [752CDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [752BFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [752BFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [752B71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7534CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [752EC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [752BD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [752B6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [752B687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [752C2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW] [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CopyFileW] [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!MoveFileW] [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW] [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW] [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW] [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileA] [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileA] [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA] [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryA] [63BCEBFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesA] [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryA] [63BCE3CB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryA] [63BCE9A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA] [63BCC1D6] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryW] [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesW] [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryW] [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileW] [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryW] [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileA] [63BCDDDD] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileA] [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW] [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW] [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW] [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA] [63BCA819] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW] [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA] [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA] [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA] [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA] [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA] [63BCEFA8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpW] [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpA] [63BCCE2E] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [63BDC49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyA] [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyA] [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExW] [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueW] [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyW] [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExA] [63BDDFE1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueA] [63BDE2F1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyA] [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExA] [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW] [63BCA460] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW] [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW] [63BCA6E2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW] [63BCAE92] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW] [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW] [63BCC023] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetCurrentDirectoryW] [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW] [63BC9700] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA] [63BC9362] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW] [63BCA1D8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW] [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!RemoveDirectoryW] [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateDirectoryW] [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetFileAttributesW] [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] [63BCDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameW] [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetLongPathNameW] [63BC9231] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!LoadImageW] [63BCC58B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!WinHelpW] [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW] [63BCCA80] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyW] [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyA] [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyExW] [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegSetValueW] [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueW] [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyW] [63BDC8E9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyW] [63BDC35D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExA] [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA] [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] [63BD91AC] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetShortPathNameW] [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegSetValueW] [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] [63BDD28F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyExW] [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyA] [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyA] [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyA] [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueW] [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyW] [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExA] [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA] [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [61449B94] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [61449B56] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [61449CF2] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColor] [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!AnimateWindow] [61449D87] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\tdx \Device\Tcp pctfw2.sys
AttachedDevice \Driver\tdx \Device\Udp pctfw2.sys
AttachedDevice \Driver\tdx \Device\RawIp pctfw2.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073 0x04 0x54 0xB1 0x24 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959 0x9B 0x4D 0xE1 0x7E ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073 0x04 0x54 0xB1 0x24 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959 0x9B 0x4D 0xE1 0x7E ...---- EOF - GMER 1.0.15 ----
Reply Hey K27,
I forgot to mention some symptoms in my earlier posts: I often get a message showing that Windows Host Services stopped working and the norton warns an intrusion attack and was resulted from DEVICE/HARDDISKVOLUME3/PROGRAMFILES/INTERNETEXPLORER/EXPLORER.EXE. Orsometime its shows the attack was resulted from SYSTEM32/SVCHOST.EXE something like that...
Here is the DDS LOG:
DDS (Ver_10-03-17.01) - NTFSx86
Run by APARNA at 12:21:20.25 on Fri 07/16/2010
Internet Explorer: 7.0.6002.18005
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3069.1061 [GMT -4:00]SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\nvvsvc.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Fingerprint Reader Suite\upeksvr.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\aestsrv.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\1-Click Answers\answers.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Dell Remote Access\ezi_ra.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Fingerprint Reader Suite\psqltray.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\1-CLIC~1\agtserv.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Users\APARNA\Downloads\dds.pif============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uStart Page = www.yahoo.com
uWindow Title = Internet Explorer provided by Dell
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6090117
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
uURLSearchHooks: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
uURLSearchHooks: H - No File
mURLSearchHooks: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\norton 360\engine\4.2.0.12\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\norton 360\engine\4.2.0.12\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\norton 360\engine\4.2.0.12\coIEPlg.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
uRun: [googletalk] c:\users\aparna\appdata\roaming\google\google talk\googletalk.exe /autostart
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Jumblo] "c:\program files\jumblo.com\jumblo\Jumblo.exe" -nosplash -minimized
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [PSQLLauncher] "c:\program files\fingerprint reader suite\launcher.exe" /startup
mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [Dell DataSafe Online] "c:\program files\dell datasafe online\DataSafeOnline.exe" /m
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
mRunOnce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq
mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
mRunOnce: [VistaSetup]
mRunOnce: [*Restore] c:\windows\system32\rstrui.exe /runonce
StartupFolder: c:\users\aparna\appdata\roaming\micros~1\windows\startm~1\programs\startup\delldo~1.lnk - c:\program files\dell\delldock\DellDock.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\1-clic~1.lnk - c:\program files\1-click answers\answers.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dellre~1.lnk - c:\windows\installer\{f66a31d9-7831-4fba-ba02-c411c0047cc5}\NewShortcut10_F66A31D978314FBABA02C411C0047CC5.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: DisableCAD = 1 (0x1)
IE: Answers... - file://c:\program files\1-click answers\html\atiemenu.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.4.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://mdev.temple.edu/webcams/AxisCamControl.ocx
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
Notify: psfus - c:\windows\system32\psqlpwd.dll
AppInit_DLLs: c:\progra~1\google\google~3\GOEC62~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
LSA: Notification Packages = scecli psqlpwd
Hosts: 127.0.0.1 www.spywareinfo.com============= SERVICES / DRIVERS ===============
R0 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2010-7-5 42376]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0402000.00c\symds.sys [2010-6-11 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0402000.00c\symefa.sys [2010-6-11 173104]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\bashdefs\20100709.001\BHDrvx86.sys [2010-7-12 691248]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0402000.00c\cchpx86.sys [2010-6-11 501888]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\ipsdefs\20100715.001\IDSvix86.sys [2010-7-16 344112]
R1 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2010-7-5 66952]
R1 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2010-7-5 81288]
R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2010-7-5 160648]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0402000.00c\ironx86.sys [2010-6-11 116784]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0402000.00c\symtdiv.sys [2010-6-11 339504]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2009-1-17 73728]
R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-9-24 155648]
R2 N360;Norton 360;c:\program files\norton 360\norton 360\engine\4.2.0.12\ccsvchst.exe [2010-6-11 126392]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-6-11 1153368]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-7-5 356920]
R2 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2010-7-5 1073544]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-7-5 102448]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-19 135664]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-2-15 54632]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-1-17 30192]
S4 iaNvStor;Intel(R) Turbo Memory Controller;c:\windows\system32\drivers\iaNvStor.sys [2009-1-17 209408]=============== Created Last 30 ================
2010-07-14 23:15:34 0 d-----w- c:\windows\system32\Adobe
2010-07-05 23:10:23 1905 ----a-w- c:\windows\diagwrn.xml
2010-07-05 23:10:23 1905 ----a-w- c:\windows\diagerr.xml
2010-07-05 20:06:00 160648 ----a-w- c:\windows\system32\drivers\pctfw2.sys
2010-07-05 20:05:52 29576 ----a-w- c:\windows\system32\drivers\kcom.sys
2010-07-05 20:05:51 81288 ----a-w- c:\windows\system32\drivers\iksyssec.sys
2010-07-05 20:05:51 66952 ----a-w- c:\windows\system32\drivers\iksysflt.sys
2010-07-05 20:05:51 42376 ----a-w- c:\windows\system32\drivers\ikfilesec.sys
2010-07-05 20:05:33 0 d-----w- c:\users\aparna\appdata\roaming\PC Tools
2010-07-05 20:05:33 0 d-----w- c:\programdata\PC Tools
2010-07-05 19:13:33 767952 ----a-w- c:\windows\BDTSupport.dll.old
2010-07-05 19:13:32 1652688 ----a-w- c:\windows\PCTBDCore.dll.old
2010-07-05 19:09:53 0 d-----w- c:\program files\Spyware Doctor
2010-07-05 19:09:53 0 d-----w- c:\program files\common files\PC Tools
2010-06-25 15:33:50 0 d-----w- c:\program files\Trend Micro
2010-06-18 20:51:01 0 d-----w- c:\programdata\HP Product Assistant==================== Find3M ====================
2010-07-16 13:58:56 48158 ----a-w- c:\programdata\nvModes.dat
2010-06-18 20:54:25 51200 ----a-w- c:\windows\inf\infpub.dat
2010-06-18 20:54:25 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-06-18 20:54:25 143360 ----a-w- c:\windows\inf\infstor.dat
2010-06-11 16:24:01 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2010-06-11 16:24:01 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2010-06-11 16:24:01 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2010-06-11 16:20:40 145503112 ----a-w- c:\users\aparna\N360_2010_4.0_Build_127_OEM90_Microsoft.exe
2010-05-21 18:14:28 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-02 13:42:25 8656832 ----a-w- c:\users\aparna\appdata\roaming\DataSafeDotNet.exe
2010-04-28 07:00:59 67424 ----a-w- c:\windows\fonts\upcfi.ttf
2010-04-23 14:13:55 2048 ----a-w- c:\windows\system32\tzres.dll
2010-02-15 19:34:56 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-01-17 21:02:56 75 --sha-r- c:\windows\CT4CET.bin
2009-01-17 22:17:13 8192 --sha-w- c:\windows\users\default\NTUSER.DAT============= FINISH: 12:23:14.56 ===============
Here is the ARK log:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-16 14:19:10
Windows 6.0.6002 Service Pack 2
Running: qb58ektc.exe; Driver: C:\Users\APARNA\AppData\Local\Temp\pwryqpob.sys
---- System - GMER 1.0.15 ----SSDT 92BF6120 ZwAlertResumeThread
SSDT 92BF5120 ZwAlertThread
SSDT 933D5940 ZwAllocateVirtualMemory
SSDT 913F8C98 ZwAlpcConnectPort
SSDT 92F70048 ZwAssignProcessToJobObject
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateKey [0x8FB1B7A6]
SSDT 933DEFC0 ZwCreateMutant
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcess [0x8FB18794]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcessEx [0x8FB18F1E]
SSDT 933E37B8 ZwCreateSymbolicLinkObject
SSDT 933D7380 ZwCreateThread
SSDT 92FBE048 ZwDebugActiveProcess
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwDeleteKey [0x8FB1C1F0]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwDeleteValueKey [0x8FB1C42A]
SSDT 933D5B58 ZwDuplicateObject
SSDT 933D7B30 ZwFreeVirtualMemory
SSDT 92F93048 ZwImpersonateAnonymousToken
SSDT 92F74048 ZwImpersonateThread
SSDT 89C9F728 ZwLoadDriver
SSDT 933D79D0 ZwMapViewOfSection
SSDT 92F94048 ZwOpenEvent
SSDT 933D5DB8 ZwOpenProcess
SSDT 9182A118 ZwOpenProcessToken
SSDT 92FA9048 ZwOpenSection
SSDT 933D5CA8 ZwOpenThread
SSDT 933E13F0 ZwProtectVirtualMemory
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwRenameKey [0x8FB1D12A]
SSDT 9190F120 ZwResumeThread
SSDT 91909108 ZwSetContextThread
SSDT 933D77B8 ZwSetInformationProcess
SSDT 92FBD048 ZwSetSystemInformation
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwSetValueKey [0x8FB1C83C]
SSDT 92FA8048 ZwSuspendProcess
SSDT 901F7120 ZwSuspendThread
SSDT 91825108 ZwTerminateProcess
SSDT 901F5118 ZwTerminateThread
SSDT 91904118 ZwUnmapViewOfSection
SSDT 933D7E40 ZwWriteVirtualMemory
SSDT 933E2FB0 ZwCreateThreadEx
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateUserProcess [0x8FB196B6]---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 11D 81CED880 8 Bytes [20, 61, BF, 92, 20, 51, BF, ...] {AND [ECX-0x41], AH; XCHG EDX, EAX; AND [ECX-0x41], DL; XCHG EDX, EAX}
.text ntkrnlpa.exe!KeSetEvent + 131 81CED894 4 Bytes [40, 59, 3D, 93]
.text ntkrnlpa.exe!KeSetEvent + 13D 81CED8A0 4 Bytes [98, 8C, 3F, 91]
.text ntkrnlpa.exe!KeSetEvent + 191 81CED8F4 4 Bytes [48, 00, F7, 92] {DEC EAX; ADD BH, DH; XCHG EDX, EAX}
.text ntkrnlpa.exe!KeSetEvent + 1E9 81CED94C 4 Bytes [A6, B7, B1, 8F]
.text ...
? C:\Windows\system32\Drivers\mchInjDrv.sys The system cannot find the file specified. !---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\Dwm.exe[172] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[600] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\wininit.exe[652] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\lsm.exe[720] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[880] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[1004] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\winlogon.exe[1092] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[1124] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 0028000A
.text C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 0029000A
.text C:\Windows\system32\svchost.exe[1148] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0027000A
.text C:\Windows\system32\svchost.exe[1148] ole32.dll!CoCreateInstance 76709EA6 5 Bytes JMP 007C000A
.text C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Windows\system32\svchost.exe[1148] USER32.dll!GetCursorPos 77B60B88 5 Bytes JMP 012E000A
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1500] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1680] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1984] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\taskeng.exe[2500] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[2612] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\Explorer.EXE[2740] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 0083000A
.text C:\Windows\Explorer.EXE[2740] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 0084000A
.text C:\Windows\Explorer.EXE[2740] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0082000A
.text C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\DllHost.exe[2756] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[2792] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] kernel32.dll!CreateThread + 1A 7661C928 4 Bytes CALL 0044A801 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\STacSV.exe[3244] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[3312] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[3352] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\taskeng.exe[3568] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 0023000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 0024000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0022000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamW 77B710B0 5 Bytes JMP 6BE7BF9F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamW 77B72EF5 5 Bytes JMP 6BFBB45A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamA 77B88152 5 Bytes JMP 6BFBB41F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamA 77B8847D 5 Bytes JMP 6BFBB495 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectA 77B9D4D9 5 Bytes JMP 6BFBB3DB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectW 77B9D5D3 5 Bytes JMP 6BFBB397 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExA 77B9D639 5 Bytes JMP 6BFBB35D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExW 77B9D65D 5 Bytes JMP 6BFBB323 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D1D 76F88910 4 Bytes [99, 0B, BE, 63]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D25 76F88918 4 Bytes [A7, 0A, BE, 63]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D95 76F88988 4 Bytes [99, 0B, BE, 63]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D9D 76F88990 8 Bytes [A7, 0A, BE, 63, A4, 32, BD, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ole32.dll!OleLoadFromStream 766D1E12 5 Bytes JMP 6BFBB657 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\OEM02Mon.exe[4564] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\rundll32.exe[4816] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!CreateThread + 1A 7661C928 4 Bytes CALL 0044A815 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F0A0F5A
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 006A000A
.text C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 006B000A
.text C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0069000A
.text C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[5456] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A---- User IAT/EAT - GMER 1.0.15 ----
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcessHeap] 00C0E660
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] 00C0E140
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DuplicateHandle] 00C0D2A0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!IsDebuggerPresent] 00C0EBE0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateThread] 00C0C260
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 00C0BBD0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetEnvironmentStringsW] 00C0BF90
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetFilePointer] 00C0D100
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFileEx] 00C0D7C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileMappingW] 00C0D550
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFile] 00C0D740
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!OpenFileMappingW] 00C0DC20
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!UnmapViewOfFile] 00C0D930
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileType] 00C0D450
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FlushViewOfFile] 00C0D690
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileSize] 00C0D240
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!WriteFile] 00C0D0C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetACP] 00C0E680
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!TerminateProcess] 00C0C110
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalAlloc] 00C0E3A0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalLock] 00C0E2C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalUnlock] 00C0E280
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] 00C0C940
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 00C0BA30
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CloseHandle] 00C0D340
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 00C0B9A0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 00C0BC80
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 00C0A730
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!ReadFile] 00C0CC90
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetVersion] 00C0E650
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadIconW] 00C0E920
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadCursorW] 00C0E8C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!CreateDialogParamW] 00C0EB10
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!DialogBoxParamW] 00C0EBB0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadStringW] 00C0E9E0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] 00C0E5D0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] 00C0E580
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [752C7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [7531A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [752CBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [752BF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [752C75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [752BE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [752F8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [752CDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [752BFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [752BFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [752B71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7534CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [752EC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [752BD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [752B6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [752B687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [752C2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW] [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CopyFileW] [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!MoveFileW] [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW] [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW] [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW] [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileA] [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileA] [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA] [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryA] [63BCEBFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesA] [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryA] [63BCE3CB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryA] [63BCE9A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA] [63BCC1D6] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryW] [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesW] [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryW] [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileW] [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryW] [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileA] [63BCDDDD] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileA] [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW] [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW] [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW] [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA] [63BCA819] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW] [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA] [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA] [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA] [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA] [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA] [63BCEFA8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpW] [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpA] [63BCCE2E] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [63BDC49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyA] [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyA] [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExW] [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueW] [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyW] [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExA] [63BDDFE1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueA] [63BDE2F1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyA] [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExA] [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW] [63BCA460] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW] [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW] [63BCA6E2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW] [63BCAE92] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW] [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW] [63BCC023] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetCurrentDirectoryW] [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW] [63BC9700] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA] [63BC9362] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW] [63BCA1D8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW] [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!RemoveDirectoryW] [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateDirectoryW] [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetFileAttributesW] [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] [63BCDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameW] [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetLongPathNameW] [63BC9231] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!LoadImageW] [63BCC58B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!WinHelpW] [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW] [63BCCA80] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyW] [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyA] [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyExW] [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegSetValueW] [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueW] [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyW] [63BDC8E9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyW] [63BDC35D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExA] [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA] [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] [63BD91AC] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetShortPathNameW] [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegSetValueW] [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] [63BDD28F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyExW] [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyA] [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyA] [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyA] [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueW] [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyW] [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExA] [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA] [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [61449B94] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [61449B56] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [61449CF2] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColor] [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!AnimateWindow] [61449D87] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\tdx \Device\Tcp pctfw2.sys
AttachedDevice \Driver\tdx \Device\Udp pctfw2.sys
AttachedDevice \Driver\tdx \Device\RawIp pctfw2.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073 0x04 0x54 0xB1 0x24 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959 0x9B 0x4D 0xE1 0x7E ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073 0x04 0x54 0xB1 0x24 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959 0x9B 0x4D 0xE1 0x7E ...---- EOF - GMER 1.0.15 ----
Reply Hey K27,
I forgot to mention some of the symptoms I often see when I am browsing the internet. It shows Windows Host services stopped working and norton 360 displays a message whenever the computer has an intrusion attack and that the attack was resulted from SYSTEM32/SVCHOST.EXE or HARDDISKVOLUME3/INTERNETEXPLORER/EXPLORER.EXE.
Here are the logs and its a huge list. I think its a terrible job to go thru this. I really appreciate your efforts.
ARK LOG
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-16 14:19:10
Windows 6.0.6002 Service Pack 2
Running: qb58ektc.exe; Driver: C:\Users\APARNA\AppData\Local\Temp\pwryqpob.sys
---- System - GMER 1.0.15 ----SSDT 92BF6120 ZwAlertResumeThread
SSDT 92BF5120 ZwAlertThread
SSDT 933D5940 ZwAllocateVirtualMemory
SSDT 913F8C98 ZwAlpcConnectPort
SSDT 92F70048 ZwAssignProcessToJobObject
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateKey [0x8FB1B7A6]
SSDT 933DEFC0 ZwCreateMutant
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcess [0x8FB18794]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcessEx [0x8FB18F1E]
SSDT 933E37B8 ZwCreateSymbolicLinkObject
SSDT 933D7380 ZwCreateThread
SSDT 92FBE048 ZwDebugActiveProcess
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwDeleteKey [0x8FB1C1F0]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwDeleteValueKey [0x8FB1C42A]
SSDT 933D5B58 ZwDuplicateObject
SSDT 933D7B30 ZwFreeVirtualMemory
SSDT 92F93048 ZwImpersonateAnonymousToken
SSDT 92F74048 ZwImpersonateThread
SSDT 89C9F728 ZwLoadDriver
SSDT 933D79D0 ZwMapViewOfSection
SSDT 92F94048 ZwOpenEvent
SSDT 933D5DB8 ZwOpenProcess
SSDT 9182A118 ZwOpenProcessToken
SSDT 92FA9048 ZwOpenSection
SSDT 933D5CA8 ZwOpenThread
SSDT 933E13F0 ZwProtectVirtualMemory
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwRenameKey [0x8FB1D12A]
SSDT 9190F120 ZwResumeThread
SSDT 91909108 ZwSetContextThread
SSDT 933D77B8 ZwSetInformationProcess
SSDT 92FBD048 ZwSetSystemInformation
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwSetValueKey [0x8FB1C83C]
SSDT 92FA8048 ZwSuspendProcess
SSDT 901F7120 ZwSuspendThread
SSDT 91825108 ZwTerminateProcess
SSDT 901F5118 ZwTerminateThread
SSDT 91904118 ZwUnmapViewOfSection
SSDT 933D7E40 ZwWriteVirtualMemory
SSDT 933E2FB0 ZwCreateThreadEx
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateUserProcess [0x8FB196B6]---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 11D 81CED880 8 Bytes [20, 61, BF, 92, 20, 51, BF, ...] {AND [ECX-0x41], AH; XCHG EDX, EAX; AND [ECX-0x41], DL; XCHG EDX, EAX}
.text ntkrnlpa.exe!KeSetEvent + 131 81CED894 4 Bytes [40, 59, 3D, 93]
.text ntkrnlpa.exe!KeSetEvent + 13D 81CED8A0 4 Bytes [98, 8C, 3F, 91]
.text ntkrnlpa.exe!KeSetEvent + 191 81CED8F4 4 Bytes [48, 00, F7, 92] {DEC EAX; ADD BH, DH; XCHG EDX, EAX}
.text ntkrnlpa.exe!KeSetEvent + 1E9 81CED94C 4 Bytes [A6, B7, B1, 8F]
.text ...
? C:\Windows\system32\Drivers\mchInjDrv.sys The system cannot find the file specified. !---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\Dwm.exe[172] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[600] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\wininit.exe[652] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\lsm.exe[720] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[880] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[1004] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\winlogon.exe[1092] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[1124] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 0028000A
.text C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 0029000A
.text C:\Windows\system32\svchost.exe[1148] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0027000A
.text C:\Windows\system32\svchost.exe[1148] ole32.dll!CoCreateInstance 76709EA6 5 Bytes JMP 007C000A
.text C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Windows\system32\svchost.exe[1148] USER32.dll!GetCursorPos 77B60B88 5 Bytes JMP 012E000A
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1500] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1680] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1984] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\taskeng.exe[2500] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[2612] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\Explorer.EXE[2740] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 0083000A
.text C:\Windows\Explorer.EXE[2740] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 0084000A
.text C:\Windows\Explorer.EXE[2740] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0082000A
.text C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\DllHost.exe[2756] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[2792] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] kernel32.dll!CreateThread + 1A 7661C928 4 Bytes CALL 0044A801 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\STacSV.exe[3244] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[3312] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[3352] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\taskeng.exe[3568] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 0023000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 0024000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0022000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamW 77B710B0 5 Bytes JMP 6BE7BF9F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamW 77B72EF5 5 Bytes JMP 6BFBB45A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamA 77B88152 5 Bytes JMP 6BFBB41F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamA 77B8847D 5 Bytes JMP 6BFBB495 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectA 77B9D4D9 5 Bytes JMP 6BFBB3DB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectW 77B9D5D3 5 Bytes JMP 6BFBB397 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExA 77B9D639 5 Bytes JMP 6BFBB35D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExW 77B9D65D 5 Bytes JMP 6BFBB323 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D1D 76F88910 4 Bytes [99, 0B, BE, 63]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D25 76F88918 4 Bytes [A7, 0A, BE, 63]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D95 76F88988 4 Bytes [99, 0B, BE, 63]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D9D 76F88990 8 Bytes [A7, 0A, BE, 63, A4, 32, BD, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ole32.dll!OleLoadFromStream 766D1E12 5 Bytes JMP 6BFBB657 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\OEM02Mon.exe[4564] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\rundll32.exe[4816] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!CreateThread + 1A 7661C928 4 Bytes CALL 0044A815 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F0A0F5A
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 006A000A
.text C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 006B000A
.text C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0069000A
.text C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[5456] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A---- User IAT/EAT - GMER 1.0.15 ----
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcessHeap] 00C0E660
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] 00C0E140
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DuplicateHandle] 00C0D2A0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!IsDebuggerPresent] 00C0EBE0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateThread] 00C0C260
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 00C0BBD0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetEnvironmentStringsW] 00C0BF90
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetFilePointer] 00C0D100
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFileEx] 00C0D7C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileMappingW] 00C0D550
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFile] 00C0D740
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!OpenFileMappingW] 00C0DC20
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!UnmapViewOfFile] 00C0D930
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileType] 00C0D450
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FlushViewOfFile] 00C0D690
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileSize] 00C0D240
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!WriteFile] 00C0D0C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetACP] 00C0E680
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!TerminateProcess] 00C0C110
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalAlloc] 00C0E3A0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalLock] 00C0E2C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalUnlock] 00C0E280
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] 00C0C940
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 00C0BA30
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CloseHandle] 00C0D340
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 00C0B9A0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 00C0BC80
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 00C0A730
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!ReadFile] 00C0CC90
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetVersion] 00C0E650
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadIconW] 00C0E920
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadCursorW] 00C0E8C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!CreateDialogParamW] 00C0EB10
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!DialogBoxParamW] 00C0EBB0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadStringW] 00C0E9E0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] 00C0E5D0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] 00C0E580
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [752C7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [7531A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [752CBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [752BF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [752C75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [752BE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [752F8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [752CDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [752BFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [752BFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [752B71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7534CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [752EC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [752BD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [752B6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [752B687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [752C2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW] [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CopyFileW] [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!MoveFileW] [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW] [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW] [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW] [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileA] [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileA] [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA] [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryA] [63BCEBFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesA] [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryA] [63BCE3CB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryA] [63BCE9A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA] [63BCC1D6] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryW] [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesW] [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryW] [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileW] [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryW] [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileA] [63BCDDDD] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileA] [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW] [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW] [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW] [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA] [63BCA819] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW] [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA] [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA] [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA] [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA] [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA] [63BCEFA8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpW] [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpA] [63BCCE2E] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [63BDC49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyA] [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyA] [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExW] [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueW] [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyW] [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExA] [63BDDFE1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueA] [63BDE2F1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyA] [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExA] [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW] [63BCA460] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW] [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW] [63BCA6E2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW] [63BCAE92] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW] [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW] [63BCC023] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetCurrentDirectoryW] [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW] [63BC9700] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA] [63BC9362] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW] [63BCA1D8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW] [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!RemoveDirectoryW] [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateDirectoryW] [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetFileAttributesW] [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] [63BCDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameW] [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetLongPathNameW] [63BC9231] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!LoadImageW] [63BCC58B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!WinHelpW] [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW] [63BCCA80] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyW] [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyA] [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyExW] [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegSetValueW] [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueW] [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyW] [63BDC8E9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyW] [63BDC35D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExA] [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA] [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] [63BD91AC] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetShortPathNameW] [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegSetValueW] [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] [63BDD28F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyExW] [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyA] [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyA] [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyA] [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueW] [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyW] [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExA] [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA] [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [61449B94] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [61449B56] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [61449CF2] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColor] [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!AnimateWindow] [61449D87] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\tdx \Device\Tcp pctfw2.sys
AttachedDevice \Driver\tdx \Device\Udp pctfw2.sys
AttachedDevice \Driver\tdx \Device\RawIp pctfw2.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073 0x04 0x54 0xB1 0x24 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959 0x9B 0x4D 0xE1 0x7E ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073 0x04 0x54 0xB1 0x24 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959 0x9B 0x4D 0xE1 0x7E ...---- EOF - GMER 1.0.15 ----
Reply HEY K27,
I forgot to mention someof the symptoms I often see when I am browsing the internet. It shows Windows Host process stopped working and when the computer had an intrusion attack, noeton 360 will show that the attack was resulted from SYSTEM32/SVCHOST.EXE (something likethat) or HARDDISKVOLUME3/INTERNETEXPLORE/EXPLORER.EXE (something similar).
I tried to post two logs on the same message window but the screen got stucked. I am pasting it separately as two posts. I guess it would be a terrible task to go thru this huge list. I really appreaciate your efforts.
ARK LOG:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-16 14:19:10
Windows 6.0.6002 Service Pack 2
Running: qb58ektc.exe; Driver: C:\Users\APARNA\AppData\Local\Temp\pwryqpob.sys
---- System - GMER 1.0.15 ----SSDT 92BF6120 ZwAlertResumeThread
SSDT 92BF5120 ZwAlertThread
SSDT 933D5940 ZwAllocateVirtualMemory
SSDT 913F8C98 ZwAlpcConnectPort
SSDT 92F70048 ZwAssignProcessToJobObject
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateKey [0x8FB1B7A6]
SSDT 933DEFC0 ZwCreateMutant
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcess [0x8FB18794]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateProcessEx [0x8FB18F1E]
SSDT 933E37B8 ZwCreateSymbolicLinkObject
SSDT 933D7380 ZwCreateThread
SSDT 92FBE048 ZwDebugActiveProcess
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwDeleteKey [0x8FB1C1F0]
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwDeleteValueKey [0x8FB1C42A]
SSDT 933D5B58 ZwDuplicateObject
SSDT 933D7B30 ZwFreeVirtualMemory
SSDT 92F93048 ZwImpersonateAnonymousToken
SSDT 92F74048 ZwImpersonateThread
SSDT 89C9F728 ZwLoadDriver
SSDT 933D79D0 ZwMapViewOfSection
SSDT 92F94048 ZwOpenEvent
SSDT 933D5DB8 ZwOpenProcess
SSDT 9182A118 ZwOpenProcessToken
SSDT 92FA9048 ZwOpenSection
SSDT 933D5CA8 ZwOpenThread
SSDT 933E13F0 ZwProtectVirtualMemory
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwRenameKey [0x8FB1D12A]
SSDT 9190F120 ZwResumeThread
SSDT 91909108 ZwSetContextThread
SSDT 933D77B8 ZwSetInformationProcess
SSDT 92FBD048 ZwSetSystemInformation
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwSetValueKey [0x8FB1C83C]
SSDT 92FA8048 ZwSuspendProcess
SSDT 901F7120 ZwSuspendThread
SSDT 91825108 ZwTerminateProcess
SSDT 901F5118 ZwTerminateThread
SSDT 91904118 ZwUnmapViewOfSection
SSDT 933D7E40 ZwWriteVirtualMemory
SSDT 933E2FB0 ZwCreateThreadEx
SSDT \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.) ZwCreateUserProcess [0x8FB196B6]---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetEvent + 11D 81CED880 8 Bytes [20, 61, BF, 92, 20, 51, BF, ...] {AND [ECX-0x41], AH; XCHG EDX, EAX; AND [ECX-0x41], DL; XCHG EDX, EAX}
.text ntkrnlpa.exe!KeSetEvent + 131 81CED894 4 Bytes [40, 59, 3D, 93]
.text ntkrnlpa.exe!KeSetEvent + 13D 81CED8A0 4 Bytes [98, 8C, 3F, 91]
.text ntkrnlpa.exe!KeSetEvent + 191 81CED8F4 4 Bytes [48, 00, F7, 92] {DEC EAX; ADD BH, DH; XCHG EDX, EAX}
.text ntkrnlpa.exe!KeSetEvent + 1E9 81CED94C 4 Bytes [A6, B7, B1, 8F]
.text ...
? C:\Windows\system32\Drivers\mchInjDrv.sys The system cannot find the file specified. !---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\Dwm.exe[172] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[600] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\wininit.exe[652] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\csrss.exe[660] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\lsm.exe[720] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[880] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\nvvsvc.exe[932] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[964] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[1004] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\winlogon.exe[1092] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[1124] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 0028000A
.text C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 0029000A
.text C:\Windows\system32\svchost.exe[1148] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0027000A
.text C:\Windows\system32\svchost.exe[1148] ole32.dll!CoCreateInstance 76709EA6 5 Bytes JMP 007C000A
.text C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Windows\system32\svchost.exe[1148] USER32.dll!GetCursorPos 77B60B88 5 Bytes JMP 012E000A
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\aestsrv.exe[1308] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1460] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1500] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\nvvsvc.exe[1512] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1680] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\WLANExt.exe[1824] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\spoolsv.exe[1920] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[1984] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\taskeng.exe[2500] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[2612] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\Explorer.EXE[2740] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 0083000A
.text C:\Windows\Explorer.EXE[2740] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 0084000A
.text C:\Windows\Explorer.EXE[2740] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0082000A
.text C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\DllHost.exe[2756] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[2792] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] kernel32.dll!CreateThread + 1A 7661C928 4 Bytes CALL 0044A801 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\STacSV.exe[3244] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\svchost.exe[3312] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[3352] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\taskeng.exe[3568] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\SearchIndexer.exe[3652] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\HidFind.exe[3700] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 0023000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 0024000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0022000A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamW 77B710B0 5 Bytes JMP 6BE7BF9F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamW 77B72EF5 5 Bytes JMP 6BFBB45A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamA 77B88152 5 Bytes JMP 6BFBB41F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamA 77B8847D 5 Bytes JMP 6BFBB495 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectA 77B9D4D9 5 Bytes JMP 6BFBB3DB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectW 77B9D5D3 5 Bytes JMP 6BFBB397 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExA 77B9D639 5 Bytes JMP 6BFBB35D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExW 77B9D65D 5 Bytes JMP 6BFBB323 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D1D 76F88910 4 Bytes [99, 0B, BE, 63]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D25 76F88918 4 Bytes [A7, 0A, BE, 63]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D95 76F88988 4 Bytes [99, 0B, BE, 63]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D9D 76F88990 8 Bytes [A7, 0A, BE, 63, A4, 32, BD, ...]
.text C:\Program Files\Internet Explorer\iexplore.exe[4392] ole32.dll!OleLoadFromStream 766D1E12 5 Bytes JMP 6BFBB657 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\Apoint.exe[4496] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\OEM02Mon.exe[4564] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] KERNEL32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\rundll32.exe[4816] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\wpcumi.exe[4988] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!CreateThread + 1A 7661C928 4 Bytes CALL 0044A815 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F040F5A
.text C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F0A0F5A
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtProtectVirtualMemory 77A74D34 5 Bytes JMP 006A000A
.text C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtWriteVirtualMemory 77A75674 5 Bytes JMP 006B000A
.text C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!KiUserExceptionDispatcher 77A75DC8 5 Bytes JMP 0069000A
.text C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F340F5A
.text C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F380F5A
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\1-Click Answers\answers.exe[5196] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\System32\svchost.exe[5456] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Program Files\DellTPad\Apntex.exe[6120] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose 77A74314 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose + 4 77A74318 2 Bytes [35, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile 77A743D4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile + 4 77A743D8 2 Bytes [17, 5F] {POP SS; POP EDI}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey 77A74414 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey + 4 77A74418 2 Bytes [05, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess 77A74494 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess + 4 77A74498 2 Bytes [29, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx 77A744A4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx + 4 77A744A8 2 Bytes [2C, 5F] {SUB AL, 0x5f}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection 77A744C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection + 4 77A744C8 2 Bytes [23, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey 77A747C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey + 4 77A747C8 2 Bytes [0B, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey 77A747F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey + 4 77A747F8 2 Bytes [11, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey 77A750C4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey + 4 77A750C8 2 Bytes [14, 5F] {ADC AL, 0x5f}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile 77A752E4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile + 4 77A752E8 2 Bytes [20, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey 77A75454 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey + 4 77A75458 2 Bytes [0E, 5F] {PUSH CS; POP EDI}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess 77A754F4 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess + 4 77A754F8 2 Bytes [2F, 5F] {DAS ; POP EDI}
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile 77A75644 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile + 4 77A75648 2 Bytes [1A, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather 77A75654 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather + 4 77A75658 2 Bytes [1D, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory 77A75674 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory + 4 77A75678 2 Bytes [32, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess 77A75804 3 Bytes [FF, 25, 1E]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess + 4 77A75808 2 Bytes [26, 5F]
.text C:\Windows\servicing\TrustedInstaller.exe[6940] kernel32.dll!LoadLibraryExW 765F9109 5 Bytes JMP 5F070F5A
.text C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExA 77B46322 6 Bytes JMP 5F370F5A
.text C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExW 77B487AD 6 Bytes JMP 5F3B0F5A---- User IAT/EAT - GMER 1.0.15 ----
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcessHeap] 00C0E660
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] 00C0E140
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DuplicateHandle] 00C0D2A0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!IsDebuggerPresent] 00C0EBE0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateThread] 00C0C260
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] 00C0BBD0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetEnvironmentStringsW] 00C0BF90
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetFilePointer] 00C0D100
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFileEx] 00C0D7C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileMappingW] 00C0D550
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFile] 00C0D740
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!OpenFileMappingW] 00C0DC20
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!UnmapViewOfFile] 00C0D930
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileType] 00C0D450
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FlushViewOfFile] 00C0D690
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileSize] 00C0D240
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!WriteFile] 00C0D0C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetACP] 00C0E680
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!TerminateProcess] 00C0C110
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalAlloc] 00C0E3A0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalLock] 00C0E2C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalUnlock] 00C0E280
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] 00C0C940
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] 00C0BA30
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CloseHandle] 00C0D340
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] 00C0B9A0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FreeLibrary] 00C0BC80
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress] 00C0A730
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!ReadFile] 00C0CC90
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetVersion] 00C0E650
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadIconW] 00C0E920
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadCursorW] 00C0E8C0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!CreateDialogParamW] 00C0EB10
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!DialogBoxParamW] 00C0EBB0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadStringW] 00C0E9E0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] 00C0E5D0
IAT c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] 00C0E580
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [752C7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [7531A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [752CBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [752BF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [752C75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [752BE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [752F8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [752CDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [752BFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [752BFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [752B71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7534CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [752EC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [752BD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [752B6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [752B687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [752C2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW] [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CopyFileW] [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!MoveFileW] [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW] [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW] [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW] [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileA] [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileA] [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA] [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryA] [63BCEBFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesA] [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryA] [63BCE3CB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryA] [63BCE9A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA] [63BCC1D6] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryW] [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesW] [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryW] [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileW] [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryW] [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileA] [63BCDDDD] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileA] [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW] [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW] [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW] [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA] [63BCA819] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW] [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA] [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA] [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA] [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA] [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA] [63BCEFA8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpW] [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpA] [63BCCE2E] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA] [63BDC49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyA] [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyA] [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA] [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExW] [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueW] [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyW] [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExA] [63BDDFE1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueA] [63BDE2F1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyA] [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExA] [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW] [63BCA460] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindNextFileW] [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW] [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW] [63BCA6E2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW] [63BCAE92] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW] [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW] [63BCC023] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetCurrentDirectoryW] [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW] [63BC9700] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA] [63BC9362] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW] [63BCA1D8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW] [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!RemoveDirectoryW] [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateDirectoryW] [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetFileAttributesW] [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] [63BCDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameW] [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetLongPathNameW] [63BC9231] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!LoadImageW] [63BCC58B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!WinHelpW] [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW] [63BCCA80] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyW] [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyA] [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyExW] [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegSetValueW] [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueW] [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyW] [63BDC8E9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyW] [63BDC35D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExA] [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA] [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile] [63BD91AC] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindClose] [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW] [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SearchPathW] [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DeleteFileW] [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetShortPathNameW] [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW] [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW] [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA] [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegSetValueW] [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA] [63BDD28F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyExW] [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumValueW] [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyA] [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyA] [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyW] [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyA] [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueW] [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyW] [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCloseKey] [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExW] [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW] [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyW] [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW] [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExA] [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA] [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [61449B94] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [61449B56] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [61449CF2] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColor] [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!AnimateWindow] [61449D87] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem] [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
IAT C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem] [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\tdx \Device\Tcp pctfw2.sys
AttachedDevice \Driver\tdx \Device\Udp pctfw2.sys
AttachedDevice \Driver\tdx \Device\RawIp pctfw2.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073 0x04 0x54 0xB1 0x24 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959 0x9B 0x4D 0xE1 0x7E ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073 0x04 0x54 0xB1 0x24 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959 0x9B 0x4D 0xE1 0x7E ...---- EOF - GMER 1.0.15 ----
Reply

kevin27_b3d29f
2 Intern
•
1547 Posts
425
0
Posted July 11th, 2010 02:00
Hi lutts,
Welcome to the Dell Community Malware Removal Froum.
Sorry for the delay in getting to you.
Due to the nature of malware and the last log that was posted, please post a fresh HJT log and the symptoms that still persist.
Thanks,
K27.