GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-08-20 13:02:12 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950042 rev.0006 465,76GB Running: qqs8jx6g.exe; Driver: C:\Users\Studion\AppData\Local\Temp\pwdiquow.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000149ba0460 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000149ba0450 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000149ba0370 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000149ba0470 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000149ba03e0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000149ba0320 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000149ba03b0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000149ba0390 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000149ba02e0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000149ba02d0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000149ba0310 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000149ba03c0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000149ba03f0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000149ba0230 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000149ba0480 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000149ba03a0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000149ba02f0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000149ba0350 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000149ba0290 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000149ba02b0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000149ba03d0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000149ba0330 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000149ba0410 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000149ba0240 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000149ba01e0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000149ba0250 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000149ba0490 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000149ba04a0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000149ba0300 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000149ba0360 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000149ba02a0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000149ba02c0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000149ba0380 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000149ba0340 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000149ba0440 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000149ba0260 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000149ba0270 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000149ba0400 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000149ba01f0 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000149ba0210 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000149ba0200 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000149ba0420 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000149ba0430 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000149ba0220 .text C:\Windows\system32\csrss.exe[492] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000149ba0280 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000149ba0460 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000149ba0450 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000149ba0370 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000149ba0470 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000149ba03e0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000149ba0320 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000149ba03b0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000149ba0390 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000149ba02e0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000149ba02d0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000149ba0310 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000149ba03c0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000149ba03f0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000149ba0230 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000149ba0480 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000149ba03a0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000149ba02f0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000149ba0350 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000149ba0290 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000149ba02b0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000149ba03d0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000149ba0330 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000149ba0410 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000149ba0240 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000149ba01e0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000149ba0250 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000149ba0490 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000149ba04a0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000149ba0300 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000149ba0360 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000149ba02a0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000149ba02c0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000149ba0380 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000149ba0340 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000149ba0440 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000149ba0260 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000149ba0270 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000149ba0400 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000149ba01f0 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000149ba0210 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000149ba0200 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000149ba0420 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000149ba0430 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000149ba0220 .text C:\Windows\system32\csrss.exe[604] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000149ba0280 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Windows\system32\services.exe[632] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Windows\system32\lsass.exe[656] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Windows\system32\svchost.exe[804] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000100070460 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000100070450 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000100070370 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000100070470 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 00000001000703e0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000100070320 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 00000001000703b0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000100070390 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 00000001000702e0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 00000001000702d0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000100070310 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 00000001000703c0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 00000001000703f0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000100070230 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000100070480 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 00000001000703a0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 00000001000702f0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000100070350 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000100070290 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 00000001000702b0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 00000001000703d0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000100070330 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000100070410 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000100070240 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 00000001000701e0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000100070250 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000100070490 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 00000001000704a0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000100070300 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000100070360 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 00000001000702a0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 00000001000702c0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000100070380 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000100070340 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000100070440 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000100070260 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000100070270 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000100070400 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 00000001000701f0 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000100070210 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000100070200 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000100070420 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000100070430 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000100070220 .text C:\Windows\system32\svchost.exe[900] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000100070280 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Windows\System32\svchost.exe[108] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Windows\System32\svchost.exe[500] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Windows\system32\svchost.exe[376] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000100070460 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000100070450 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000100070370 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000100070470 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 00000001000703e0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000100070320 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 00000001000703b0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000100070390 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 00000001000702e0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 00000001000702d0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000100070310 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 00000001000703c0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 00000001000703f0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000100070230 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000100070480 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 00000001000703a0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 00000001000702f0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000100070350 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000100070290 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 00000001000702b0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 00000001000703d0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000100070330 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000100070410 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000100070240 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 00000001000701e0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000100070250 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000100070490 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 00000001000704a0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000100070300 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000100070360 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 00000001000702a0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 00000001000702c0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000100070380 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000100070340 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000100070440 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000100070260 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000100070270 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000100070400 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 00000001000701f0 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000100070210 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000100070200 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000100070420 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000100070430 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000100070220 .text C:\Windows\system32\svchost.exe[608] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000100070280 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Windows\system32\svchost.exe[1568] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Windows\system32\svchost.exe[1884] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Windows\system32\taskhost.exe[2092] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Windows\System32\svchost.exe[2124] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2204] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Windows\Explorer.EXE[2428] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Windows\system32\svchost.exe[2916] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2984] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000100070460 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000100070450 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000100070370 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000100070470 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 00000001000703e0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000100070320 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 00000001000703b0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000100070390 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 00000001000702e0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 00000001000702d0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000100070310 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 00000001000703c0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 00000001000703f0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000100070230 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000100070480 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 00000001000703a0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 00000001000702f0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000100070350 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000100070290 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 00000001000702b0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 00000001000703d0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000100070330 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000100070410 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000100070240 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 00000001000701e0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000100070250 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000100070490 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 00000001000704a0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000100070300 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000100070360 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 00000001000702a0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 00000001000702c0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000100070380 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000100070340 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000100070440 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000100070260 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000100070270 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000100070400 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 00000001000701f0 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000100070210 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000100070200 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000100070420 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000100070430 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000100070220 .text C:\Windows\system32\wbem\wmiprvse.exe[3592] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000100070280 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Windows\System32\StikyNot.exe[3968] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Windows\System32\svchost.exe[4788] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[4920] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 00000000770f8781 8 bytes [31, C0, C2, 04, 00, 90, 90, ...] .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000100070460 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000100070450 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000100070370 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000100070470 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 00000001000703e0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000100070320 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 00000001000703b0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000100070390 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 00000001000702e0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 00000001000702d0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000100070310 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 00000001000703c0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 00000001000703f0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000100070230 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000100070480 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 00000001000703a0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 00000001000702f0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000100070350 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000100070290 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 00000001000702b0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 00000001000703d0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000100070330 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000100070410 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000100070240 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 00000001000701e0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000100070250 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000100070490 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 00000001000704a0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000100070300 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000100070360 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 00000001000702a0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 00000001000702c0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000100070380 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000100070340 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000100070440 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000100070260 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000100070270 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000100070400 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 00000001000701f0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000100070210 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000100070200 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000100070420 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000100070430 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000100070220 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe[3076] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000100070280 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe[3464] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000077d80460 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000077d80450 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000077d80370 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000077d80470 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 0000000077d803e0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000077d80320 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 0000000077d803b0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000077d80390 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 0000000077d802e0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 0000000077d802d0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000077d80310 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 0000000077d803c0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 0000000077d803f0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000077d80230 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000077d80480 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 0000000077d803a0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 0000000077d802f0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000077d80350 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000077d80290 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 0000000077d802b0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 0000000077d803d0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000077d80330 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000077d80410 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000077d80240 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 0000000077d801e0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000077d80250 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000077d80490 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 0000000077d804a0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000077d80300 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000077d80360 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 0000000077d802a0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 0000000077d802c0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000077d80380 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000077d80340 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000077d80440 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000077d80260 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000077d80270 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000077d80400 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 0000000077d801f0 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000077d80210 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000077d80200 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000077d80420 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000077d80430 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000077d80220 .text C:\Program Files\Speccy\Speccy64.exe[3400] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000077d80280 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077c1dc60 5 bytes JMP 0000000100070460 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077c1dcb0 5 bytes JMP 0000000100070450 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077c1de10 5 bytes JMP 0000000100070370 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077c1de60 5 bytes JMP 0000000100070470 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077c1de70 5 bytes JMP 00000001000703e0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077c1df20 5 bytes JMP 0000000100070320 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077c1df50 5 bytes JMP 00000001000703b0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077c1df70 5 bytes JMP 0000000100070390 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077c1dfb0 5 bytes JMP 00000001000702e0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077c1e030 5 bytes JMP 00000001000702d0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077c1e050 5 bytes JMP 0000000100070310 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077c1e090 5 bytes JMP 00000001000703c0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077c1e0e0 5 bytes JMP 00000001000703f0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077c1e240 5 bytes JMP 0000000100070230 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077c1e400 5 bytes JMP 0000000100070480 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077c1e430 5 bytes JMP 00000001000703a0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077c1e510 5 bytes JMP 00000001000702f0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077c1e520 5 bytes JMP 0000000100070350 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077c1e580 5 bytes JMP 0000000100070290 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077c1e610 5 bytes JMP 00000001000702b0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077c1e630 5 bytes JMP 00000001000703d0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077c1e640 5 bytes JMP 0000000100070330 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077c1e6b0 5 bytes JMP 0000000100070410 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077c1e6e0 5 bytes JMP 0000000100070240 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077c1e9a0 5 bytes JMP 00000001000701e0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077c1ea60 5 bytes JMP 0000000100070250 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077c1ea90 5 bytes JMP 0000000100070490 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077c1eaa0 5 bytes JMP 00000001000704a0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077c1ead0 5 bytes JMP 0000000100070300 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077c1eae0 5 bytes JMP 0000000100070360 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077c1eb40 5 bytes JMP 00000001000702a0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077c1eb90 5 bytes JMP 00000001000702c0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077c1ebc0 5 bytes JMP 0000000100070380 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077c1ebd0 5 bytes JMP 0000000100070340 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077c1eec0 5 bytes JMP 0000000100070440 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077c1f0c0 5 bytes JMP 0000000100070260 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077c1f0d0 5 bytes JMP 0000000100070270 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077c1f0e0 5 bytes JMP 0000000100070400 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077c1f2a0 5 bytes JMP 00000001000701f0 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077c1f2b0 5 bytes JMP 0000000100070210 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077c1f320 5 bytes JMP 0000000100070200 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077c1f380 5 bytes JMP 0000000100070420 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077c1f390 5 bytes JMP 0000000100070430 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077c1f3a0 5 bytes JMP 0000000100070220 .text C:\Windows\system32\WLANExt.exe[1320] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077c1f480 5 bytes JMP 0000000100070280 ---- Processes - GMER 2.1 ---- Library C:\ProgramData\GG\ggdrive\ggdrive-overlay.dll (*** suspicious ***) @ C:\Windows\Explorer.EXE [2428] (GG drive overlay/GG Network S.A.)(2013-06-16 16:59:36) 000000005c080000 Library C:\Users\Studion\AppData\Roaming\GG\ggdrive\ggdrive-menu.dll (*** suspicious ***) @ C:\Windows\Explorer.EXE [2428] (GG drive menu/GG Network S.A.) 000000005ff80000 Library C:\Users\Studion\AppData\Local\Temp\speccycpuid.dll (*** suspicious ***) @ C:\Program Files\Speccy\Speccy64.exe [3400] (CPUID DLL SDK/CPUID)(2 0000000180000000 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xE7 0x12 0x16 0xB5 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x6C 0xC7 0xE8 0x0A ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7F 0xD4 0xA6 0x76 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xC0 0x81 0x71 0x41 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xE7 0x12 0x16 0xB5 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x6C 0xC7 0xE8 0x0A ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7F 0xD4 0xA6 0x76 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xC0 0x81 0x71 0x41 ... ---- Files - GMER 2.1 ---- File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3A2895D8804DA672F10CCCBA53C21973C90B555F 6209 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\21BFA2A87FE4998813F87690867A0A18FC5F1BD6 491 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\22188EFCCB8422B3EA3F445BF93C96DF48FAC759 4185 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7DA5A1CDE59298E250EB5C9A8A0950A48ECF8711 14772 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\0375A45E919540F352FB187C8E9E3BD000FE3F99 9540 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\45802D245EF09B623D4E1787C9FCAF59376BECBF 45608 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\0A448EDDA2A62211242F3EE250D79BC73E5BC285 62306 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2A8C0C59135A5C37CB4F2D6F9B3F83BAFFFEE334 22301 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F69752F7B74009AB826ED8A76CD4E45E48064A38 954 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E3A307F67710D1B215D8498722FC1EC626EC69DC 2233 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\A48D8DC2FC4B88D0CCA34731F9D3195F9917CEDF 5616 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\5E0C3F2E648049D29CDBA0624140535BAC0B50B9 25958 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\57B6D4935ACA49C1B79E87A0D044C23115331AC8 130417 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B58AD8512D983A3E2175127B9CDC33355ACCB042 23155 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E811ACF8F64243C9E9A7E2533BAF0341319C0906 3654 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\78AE20D5BE8BBA5F1766B404874B6B250EC407B7 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2752050652997FFB2633057B0F5235BB1379C726 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\4279A521A97F114D765883AA5AFC991A943ECD10 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2467CEED679F66DB233D042722441BE763CA1605 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\1D529DAC23C65A839BEF1FF5642AD2468FF9AD99 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\0C5705AA5FD9D55DEE0BC85CDDF4050C16642D5D 9463 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\10BC03728ECDEB86AEE3481ECCE2246BE577457B 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F4575F0351F82DD95F140C0B4B78DA69300C0AAD 4985 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F465F701C3180B9C9A81FB3366F60E1DD541FB14 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F4728C0336BBD55684D8C53FE4FDFDDD5E0A639E 2455 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7FB903A56B3436B982D4AF21D413DE064D78E438 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\0B1B77B470118FC443D03440AD6DF9E30E484B67 5814 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B91827974A136CEAC02F3B734A4CED0FDB45D602 946 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E02266FCDEDDFD653125ECE38E251A7E3D29BE04 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\A5EDAFBC908C2CCB35FA500DAADE26EA3B460505 11160 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\A61C6089E2DC8F2F53A2C0FBD2D1075E9CA4F32C 4149 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\80FC2354C9D4492B1B47EB0488D1A22A0E99C49C 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\EC72DD712A9A8BBE786058A38FF0CD57E028B690 894 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\9B6EA532A68AB2CAEA0412BA5F2FE865334F82B7 26235 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F71BB0B0B7546159854BB4666B2463EC89C2E014 4249 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B334DED26D45AF28A6DA43E87A889AD20331BC3C 29548 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E359C0CED91E46686B8CCD56DD3006A5F7BADFE9 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E11A1CC32610588CA9CB23EDDB8501594B7FB5EB 1142 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\599C2FD6CEAA3D6ECA50A1CA882E0B883A75CCBC 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\BEB2AE04BBB741EBE41F81F5AEC2AB8A3E5CC764 5124 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3EE8ECB1900A0392F295896D48ABA288B5971711 1110 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\829ECC8829147E81D4B1B354FA1BAEF286ED55F7 9419 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\607A00FDF4D6E07A53DF471A6F3BACCE0EC9E067 632 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\CFEE226E04219867F45FBCA465ED41DAFFD65F9F 775 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\A0BA579A07D20DA718A7047E5F3862FB833CB77A 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\A0DFA02F2A0A8D829FF529951835D6B4CC336F56 46529 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\5E50BA4E781A2F0A0824B27551D5BD0A2E85777F 10990 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\70F94C20A9996D27D181229FD7611636F1C13085 5934 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\711FC3415324A966E8776CCB2197973922E0226E 1173 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\09B14AE22C17DE44780B244F51269592A6595BF1 784 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\09D9AF432D233143EEFADB6F28CB18F1B964C0AF 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\FBDBB249E566B921D2C9B02975626123A48EEF75 4140 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\6C5F986ECCD8E60863926200539566F4BA0165B2 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2B06D3D1CCC26B657C7E6EE041B0DFA98D97BB0D 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\89D494E144A8E3E676B038705C1D5BFE4B70776F 544 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F075ECD54F972083F4935947F5643009F8D7E9FE 7348 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\1AEE91936F89392B984367CF8870700869CD8A06 1517 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3444D5AD52039205DB51A3FDDA2A628ABDDBF708 2865 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\736457665B773CB9F51F675743AF9A45E86886F5 75832 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E24C555BFDAE03D41014CAAC8DFDCCD019BB2CFD 4273 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7B831E147657A52579BA4653AC0F8F742AEE9B7B 119127 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\FA689F9E2991689E7CF9B81002B8E4695C0513C1 6298 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\56B92985E440AC5C65DED5D53DBBABF61FCBFDF5 1743 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\56C7B2F0EA47F78E735F5E2C1FA2BEDD2796D991 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\56D556010D2EBBEA95B9905D3F3D8104BC40284E 557 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\56FDE7BA0D5EE2AB6CCFDCF5DA1A5BED339AEDFB 4228 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3D4616A0009D1754D000B395C8602D290FDBDB94 31880 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3D561B12F4C64CC2F7697894C54F9379BF53D41A 1378 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\09305D92FC611DEE87415FC18FDA10C2938A66CB 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\093733555B50BCA4293B0472DC545318A348E0AA 1512 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\18FF622F9704DA68709CB7109B10D2055FF73E9F 628 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\190DC36602625EA7B7237449D531109ED16A3EAF 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\DBFCE9F178ADA777B003049DCD512812A5EADA8E 2731 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B6C7351F0FB7445512CF9167150D777F06C2573D 10562 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\98C56EA737AEBF61E70342DA9068F0D83D2A99B8 7484 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\47D4F5BBEE28B4C0F9C51A59849B484C96E6C4DD 29480 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\47E4997D631DE666EBCB09D53EA01C0480277159 1120 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\71FF821F5A253A568D2ADB8E9FD0A8732D1B329C 54485 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\6F00F82B2583CF79E8DAF1839F41B0AD9E710521 9162 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\8428DF566ACF15B320B851A511D0788DE4795707 40860 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\84364C84859DF5AD70FEAEF572FF47E993272F58 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\4FF2E97F28665079B6F4CF4C1FCB60DB5E77D10A 6289 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\5A852DC46EF502D1CBA752253AD8C8BBE70F6617 1082 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\5A8A11B7674B0AA3EE63AC52CA3F407FAB7655A7 797 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\0809B8691A21D85E3547D2243C88596105EC109F 1507 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\EB46700B5233ECC5DC9B19347E464E0B375BE177 82787 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\17ADDE220C6C6BA544C91290C3166BBE8F2B5193 317 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7DD363CF22D4AEB5FFDC64555BDF66869F3F390B 122465 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\044817E480D2EECD3908EA516913FF1205BAEB71 4690 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\8560B4CADE4BCA6E4015A3C453D7943CBCDAEB2E 9891 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\66C3AFCE07B571B3780EEE2D660B12B457625EA0 7189 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\C96FE65FA321414A6BB862A30DECED8C7CB3363B 7199 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\C98E9C9143DA43F74A4842802D048AF0EA5D3A18 33237 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\6BA741AD1A2057432F9E93FD6F6FA18761FA6EE0 133951 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\5CAE28CEC543237AEECD3431A5FA393A62B9F53F 1315 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F1E33A9AD30380737F5F3D4C0CA43BA50F3334C6 6889 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F1EEF1FE58C83A5AEF4211B7259860B86CC6630A 1549 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F2053AA74569776DD5DCAF672DC1DDE9E740E7F2 8059 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\68278D9FE19AED628DAF353C8C34110E0CB8A306 513 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\6DAC18D0BB71E3234A09989FF0BFB7C50DB6D7DB 1749 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\4475AF212D8908821C7DEEE53209890954CA1D5D 8849 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\FF9654F783113B0A32FFCDD8CDE1FB1E8CDFE68C 9505 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\11B605028B58F3DF82473799F3310296ED4FBDCB 4247 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2F5388108693C3280E71CA823EBF6B3A8BED0C4C 6858 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2F63D358F90CAD819600DE942274A0F9AD384E1D 23900 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7D6C189029B6EFE985DC0BFEFB8E92126EBC4945 22309 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\CC893D82207759C666E0255707B494834DBCF166 633 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B4186B3566CE76368923D3F09B0D94444C698DF1 3506 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\40D908BA586B024BF71C1B0D57258A45C0973CA7 1038 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\D83089992CC700433ABE6846ED5BD18DCA9A2FD6 24574 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\37CE5023D0BD53FBC0CA8765A5DC3D997F8A2289 22126 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\A917F626888B104C4687CE935B725A7A6D5DF995 5390 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\A94F1B8E005BACF81D7A4447E5CB5F4EE93874A7 631 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\A39354161B81470BB5482A3C2B6621BC99D3197F 647 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\D21DE55E8587861A638B58735B4F81DBD65BF967 596 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2229D5471C218DA69A69AFD109CD17364B55D836 7302 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\224BE831DE6D3B5ADB2562721CF0C4CE6FF9C6EF 1634 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\C45F73D66214C1B5091FC69AE13E105A2D010BF8 101175 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\C78B3C7C1D52B993ED8F6AB9DCE739853920A3D8 758 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\C79A8530AC15C18A321F9290BE69AFD59A5DF611 715 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\92F18D795E586B24F79DBBDA6DA10DC52783B3C0 1526 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\A41CAAD8988ED5B5C29AF8B2E89C9FE51F5E9B0D 2387 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\616DE5340449D0D03F2C29F49767912B266B408A 25870 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\9BB18AD834E11677D7373916392C8046268162A9 127821 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2838095C63CEEF320FEB50343731D7EEC2865D53 36847 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3A1B23CB2380B05779FCEE6F4F59CA9B7A0794F0 5959 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3A1BE6102CE3F5D78EBE203D6CC4D053B6BF38C0 9591 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\ABCE78F6BE7AFD871FDA7AF3BB0F2CFCC90C4978 43992 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\1F9B7B3308DCC37108A5B7D2535CCF4CD29108A7 2947 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\1F9C5AC3FCE3C9F5C512C5E56221B19513CB824A 19799 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\1FB6A775B82ADB269C1961FE3BF26E1A0F363703 320 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\A8B9BFFFF236A34D82AE5730B7BB8DB39B095573 15147 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\290CB7D5D1167710997CD6E90D02B1267F67C85C 12548 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\1604420FB35B8A323A4EFAAE94DE92C3297CD4E4 12551 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\6CB21DC33A84D0B3F89E881376814334A2FE9D37 10319 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\451D61033323FEE15A3544FF101FDB576023DA75 4146 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\4551669BEB0287FCF9A76B059FFDA005578FBBAD 1567 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\771B222CE8CF92C6499D334BDD3ECB4EF71D18A5 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\0A19F314726267016DF3DF9336829BFEB91D6CF2 1575 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\36D48D92C752D9264CBD1FD5683865026B5FC07C 839 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\36EEBC36D6672090FC094537D60DF8662BBB3B2E 82784 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E158CD1BDB071016CDD7C025A84E610BBF63D555 2406 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E165485BE3F04BA74055CB6B57BC4C8275D4FDC6 111046 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\59E738351D76D5006A3576C5201CDF636D6E5208 2264 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7250FA073CD41AD8D1CDABE3E620D756498E1D87 18241 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\CFA1B0E89CB5F639B40BE3B33DD19008FDBBB01C 467 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\31513CDF67120538764FAC195DF0272020E0A9D3 2659 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3165C78677928A83BA4C2AAB5AA9FD6DAAD51605 1734 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E310DE300F3986D80F16B52C024E0FEBF20C14A6 11291 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\CD5B2310899E4EBA6CC20F80C8997C66BDB8BF01 557 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\0AAE4D71F35665FEEEE1EE55F51DE131C3133C4D 2859 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\0ACBD21A23A02AC36F57FC2CD627B2E953FDE4EA 8471 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\92339B427783E3F01F737EB16452A150E23CA57C 1494 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\50B97C3DDDB1F5309E881EE872AB9E44D2675BB0 4920 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\50BCCC75509338D10D8AEFE7EA69FB09E1317E05 21174 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\D73F183F0F9F3D3DFDA5EAD930E2F0DB71B9B943 13254 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E63CE0D29ED22D7D35B07CF2A5A2EF94A416AD6F 318276 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E64816B7B49C5C838BAFB76D1303CCDE32065386 58580 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\4763B26B11F9E06C808594373A0A96A57800431D 1138 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\478B665DADC7735AA2142772D18F315E8D4C6D28 32102 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7914A428C47CD0D5FFE76254FFEA6CF3FC62EDB6 10244 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7917C84512A08CED1F46A48B2B8AC5D75B9ED8AE 6961 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\16EDDAF0573655145BFB0F91181DCE99905CD0FB 1485 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\172BC3BC8BC78608FB449DB011DF73D6C164B0B7 7290 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\6A97B2F9F1EB892F673E75016858E4785A027F42 104830 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\A4C6ECAF0D4C45A1DABF5D19C284D655BE526D75 4834 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\A4CA74C3E7B26A202003A122B137618B055D2226 3910 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\545BB594868541BE344D61B000A8287961D6E89A 458 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\4F11A1E36B62A94CB1EC177C15B6864ACDF7CE0C 49341 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\4F27F033725739DF906E43A2898246F11D913D51 9679 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\C2D6B92FEA14840118079D343EECD89BEE906780 5673 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E7B22F03AC3ADE1A75E468B9C48A4239DCE8961D 5782 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\8B65C0FC86BF4F1F6E7A26343912356F03091354 6627 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\8F9B3F7783555724B86D486000C25B443F85B8E5 21523 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\C1C6EC231A8E3844EA5DE236509CB3723BE9853D 3417 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\EC5983B3551814B91451B0AA220A69E7B2C6A95B 10046 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\AAB0C074F872F5BD214D7CA9E26546CB09F494C3 11938 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E038C1ACDEBA6BD2C80F22A3D84E7DE7B08CA6FD 1133 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\AFD60D0AB59DE1CB9CD35D8F5A8230485E801FFB 669 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\82A10ED55A1C800629B58B08D6A6711E16D6B831 2062016 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\ADE6BAF9ABE5D0FD0D380CB05F733F34DD8B588E 1459 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\AE0E451CD726077CCF86EA11AC3110B93ACFF36B 33782 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\5CD6E757C4303044C18EF3A8320934FC721920F1 408 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F8D1151C37D24AB950271506C817F5DBE16CBAD6 2578 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\08EB7199F65F62F6F55698E256D012823CE2A123 1933 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\08F0B52D2BAC664F6BD0F68F0DA4A09F83B24055 2658 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B2BBBD06EC00415775D72C67E89AFC877F21B0B9 966 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7CACDE4690D429EB18BD64D60BA065E5B64B7413 3360 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7CCC051C4A8CC7357FC3D179FE992FFAB5F98E66 5309 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\C88034217FD4EDBC59F0923925957E834C14802B 2643 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\BD270DFC697187C864409C098E83C88D751655C5 539 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\BD46BCB021F272CD851111E6FDF2D261D4D13259 27772 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\1B577FB0E21A308B176073279A2959605B63A614 4517 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\DF7EC290FC5BD0509D7A79FF444A65C95AC39AB8 641 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\42436DD5B216694C8ECACA2DD8D27685AF5D9C99 5893 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\1A093D38619280B96D93A5AFAFB7F415A5CE37D7 1628 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B5F36A72AB3280F1D79315761ACB4ABBF9E81EED 173988 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\762C8C8D6B4C4050C1539866D8985735BDAA10E8 3333 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\277EE87F81930DB8459A5CC4A5DEAD17EA744A39 1655 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\D7EA147AF2076853F1C395FAF7618C40B5CEEAA4 1629 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\0846C99938F28B1F271AAA2FA8603CA23E2836BE 10150 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7C3D1AE2267A680DA97B96FB89A9E135F4E07E82 24535 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\9CFBA084EE31CA4767B90E24514F9E8662FA04EC 109683 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F95B2F46E47C1C87108C7BB1B882A4C3F8C49698 1726 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3530B974E79192E59F1E1C23F282CA78CBA83CC7 125865 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2B67191F8AF038D611AF27A3D3B46F4BED54EF6A 2330 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\54F4F29D4757A8BBD2A41361D28FABF612E64C37 2656 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\1411D27FC190E38C2964F1172193132438BD6BEB 36756 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B9ED20B592BEAC42F0E6E6697B0128B9063CF9B7 21925 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2060F70701FAA07A3B62B89B66F0CA4D8F1B297F 1074 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\C52F315BB655A7A0E9327E34AD869D2CB2FA9CEC 1385 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\C547730185B67BA2316357569E57B201421EE78C 32463 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\D35C29BD4C440887EAF996B5D3D91F921C825EB9 13570 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\BED86BDD81211407D2EE68AEFD946B5CA97F056B 1000 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\97807896F8DC079714E7B33B40741DD0BE8706AC 965 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\0E098C145326452E1E90EE0D4DEDDC9B77C9111D 631 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\4DCEB3104D9C85E9726631053976A2C6771D767B 16222 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\D12A1C722C23ED18FAAE991447406A117920966D 62342 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\1D0E4A8A1CA2E269FEA143AE05ACDC265CA1C910 5138 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\38721E185A9F73D5BD49EE07544B1B143A7A0FF1 10251 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\387DB46A893233A13657562B38B0A22C63B11976 4759 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\C8FDFF899B53839CC49E800EBEB0D374CE20B5EF 1986 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\726E88A4479AE1DF65013C9622C97C2FB8455ECE 27543 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\90A4266B813DD225E6EFAC03E9F1A61E09AA89C2 6711 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\658CF3B9B0DCE80B9F9DB1B95D88DCB304A6E4C5 544 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\65A5EF097B8AC83E0C9FC09418242D30CF458D1E 6808 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\65DAE03F97D6C0E6CA705CA7CEF2E249AC6CCEAC 2526 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\65DBEAD6F331C5116B4268E9F8303ADD38E21687 19707 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\EF880D0D7DD274ED98CBA514740A190BFCAB6E21 25424 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\36573AD4D761D17E31469DC4E439BDE26228DBBD 2512 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\06E53AE6A8A5C1591CB8F00889B21687CEB49DEB 5800 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2B9D7FD43F9A8E16C728F8D46D80A3370726B2BD 899 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\EB35E519D1EA305DD1E5AB371793EA24B9E2F75E 570 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E6C80AEE44C5F03B8B3B0093C4E3DF58308505E8 5935 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\96C895EC1F3D45C3992E79143FCB38D5640596BF 19668 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\96E75141619D5F73DA0CBBDADCA57D7C9A78C684 30740 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\73D3DAC28D5961EAAF0E06261BF812476440E50C 21015 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\61E4F8472A00C8C01285DAA3E174A49535BF45BB 21788 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\9A20DACDD9F795A58F57D976D2A8BF020BFCA1AB 126892 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\D0DBA22AED81870BA8DBAD328F03B3E0E3600627 6306 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\718CA49E10EF4EB31F16292AFFBD3BA0B6F8F06D 100948 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\CB14B748D2D9DCD1756F5D6591BFD1C788D25031 7611 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B66E0A82BF65E2C93FF9F87F2CE1C403AC8F3B3E 1095 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B68A0FA9613BE57D63379B22365E7E9181F25793 1539 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F6484F2EE44E45AEA886EB7F6124B2F8A2DFCA06 1134 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F661BA3AA6DD9A4A4056FE24853C05C695958A06 5441 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\39C5444E4719CBE945813B7693DA7D712A5CEA31 245131 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B8AA88307D5EF1F06DFC1C9130F7730E2A2B7AAD 44395 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\D00D1568851F0D22E210DA9BF941D04759E70D3B 43599 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E866347EF0F491B05A008A26BA9A6C44E373E11D 2577 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\258E982BFB7DA6C4EE1F6C03759FCCC52E741410 123826 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\79B5E818EC63B063FE794E011B3A1258B9DBF27A 40525 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\022BB5656E7C20B7746448AC4C2F9BCD213C2B3F 1602 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\821990947EC6265B138685FF2B90566598E5F9F8 1137 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\17C1B4CE5C1FD21B945F86DB4F10AFE641BB7675 5177 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\17CF519FDDABD297AC6F050D56E4EAB9A3DDF5D6 10700 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\DA8CE179B9E669312F0BF6EE28F3B5CA6DD4421C 9994 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\4F61627A32D97382248E50EF96321B5D924B5031 4279 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\45156C6CF0BC6C435CCA856A207E559F908CEF73 1189 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F3445FE0CCF613F9CFC63FDB98486C4404B891DA 2551 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\24044D78FFCBCC349C89D6D3DB46D8E7AF4C30E4 114196 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\102B656D066640784241B472408A6B378BE9B7C3 35279 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\64277D60251093A3D7F5530957EB42781C2C534B 767 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F6B5E33D2DB8BDB8D11DFDEAE5BFA277E7D6B901 64226 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\41B3C4F6CB52A9A1331C08C21A74B8AE0DB44A0F 1837 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F41CEFBA4B2C5C556E89A4740D8D8C81D901F3FE 3707 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\04E28F2013C1A6C4A699D2F17F1E86A735B438AE 2863 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\1E780215431336EE69270DA2B602585C34EDD5AA 1201 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\64B15F0C8C585F90EAEB21C3131E13FF94DC67A1 1203 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\FB31F6B81E24AF79B8E1AD3D27E0DA38D36DF6D3 680 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\5C1824FF00C1768A5854E519EF4047D72E69FDEC 55021 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\0753BC5AB6E2CD0F162BE87EDA9105DDE514A22C 1222 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\488C32875CFC6E3C66B9BB0C1F92B517143CA245 98504 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B26D9E970580B03BA095AE815A4D9F48689BFC45 9005 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\66342D0205D99DF7AA2BA0B40BDD5CBAC6D1AAF9 19979 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F487301A29EB571523376E6BEF362A9DDF18BF66 33895 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E499D20C12005087ACC3D52BC91A84488A846ADC 9745 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7850B6FD55A50C7E1737B8009F77BD6FDE0041E0 1749 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B8067551511C5D760B8A23954794B885B9E5D0B0 3762 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\6C83B2D27270A16F7263ECB5E508EACD582FA387 1411 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F5FD217D523531EA3B055B885E8FA5481D41E7EC 37223 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\40633D9E3CD8DA38EE597DB0E8FB13ABCE3E7BC2 588 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\DEC5AFA8089996FD7A02DB33B92FDC6697F52744 1542 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\DED023AFFC890BB47A3E50E053C2A334C2FB5DA3 4011 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\DEE0B0FFA1F0BC4F24CAE843FD70940F1E634982 106858 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\C59864206EF724E0131215F21BDFB7F3B453D913 9584 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\29D935BB53A47868AE7C84FF7A1E58D8EFB56C46 6405 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3CE505E6707F6FE6F87F99089D41BDB0A5F14438 2643 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3CF07EF63374AA16DA1C50E5A874F89E845BFDA0 0 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B108DB6FE59EB9979B8909402D9C4B8A24C99519 1214 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\B10A8B39812FC321C0B3784974D3668A4F163A0A 6495 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7DF3F4707B03E35849E8E9CADCF8405886EE7B09 11338 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7E02C0401427FE82C2CCC29C8EEC94A76205CEB9 662 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\7E092163CA35E06B7E1BA0B83D885B0F3B7EFC67 1367 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\555586BFE9F194668A106C7167710EDF8A862787 30180 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\5578C7C0D06BD2650FA7353F91D5B764FC4E0D44 1441 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\A7ADDD4025156558BE114C2A46D55E5EF525CFF4 23680 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3B9D79DC501149918FD1890C264D829822E2877A 1522 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3BADA33C82C127DBC6F47A247F985F4FC2FA989D 1078 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3BBD09E79C9200763D25450AB4CEA186C48C84F5 120444 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\904D675568BD5096EC94ED22C8F48E7F50E51CB5 1665 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\670EC354AA50EE0B4F78C675A6DFB44422295DF4 15981 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2E4DDA4CE7B986026CFE1BB56104F65071D92338 1680 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\508838E12F7939958E78B23B9D634EBED9E9C73E 470 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\86D64079938D91999E03B851731E0E0415D49EA2 47276 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\86E909183CBF823742885A616803B50230AE8F7F 7081 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\8A184A2934381E192A79390838958407EFEE31BD 2968 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3732383258257A02FE5868C64BD5458DB9471663 7362 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\A9A79CFDC1A406C57AB4928E34629A80D048B743 6541 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\AC1B9A3FB264759F483FC2A8F7D5F814D6F9F636 8606 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\AC30E710A3EB22124A77EBC45BDBF2C830610987 127374 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\68F697505FC72E88860BADDD8A7CEB9E1A8F59F9 1512 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\1FD451BF5BCA90C58F1EB3C5A2A99BF3D10A2814 4142 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\C9516979C971B23B04EF6DFDD1B34052F1471FC5 29804 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\0554C70219C4A62AB700A4B0D3EA4379B9B9189A 691 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\0162A60E43914E2F9D1C2CB9F40526C589644E63 108445 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\0FED735FDF6F8AAACA59EB72F3A2511375E0B4EF 1485 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\4CAB78E944532A27BFB5F4E13C9584482A03D6E4 556 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E5B97C0A98C2A60576E58C5270C8CEBC0567BE85 2641 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E5BE632907A0035F3812A6812B893A8368B80144 4141 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\C9FD01E283ED7805C97A62BA932227549882563F 7588 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\CA0322672EB7D73BD248E56DF597F5C23E706286 6167 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\78D7658B8C679AAB1900EF6EDE7FC9CB83D2EA5D 11462 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\92AC97A21FC77B5338FB160040E39B580AA926C6 75725 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2D90D538F156ADC15EEB6C801BC420355C189A33 26110 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\FACB4492F557E23E07F1115C24A0B3D787FB2C96 2645 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\42068B148F813520C71272AF0D4E0FF6BCAA6859 59834 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F012C3CC3D9B7516DBF755149F531D472540A251 1045 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\F01B0068CA6308EF6E59787CCDD76E04F5090B5E 2585 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\3502DECDB9C8111D78D3015C99273E1C02BBD18E 40525 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\696051845271071402448EA818C9BAD0F58E6C23 10505 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2F87A3BAFE355973FF15BEC25D42C68D785067A7 11887 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\07E62333E11A1363D65C3C536F391EF26C196C73 1205 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\2188DBD4926A019FDBB50F671A3CA7D3E92D1EA5 9556 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\E9B80DC8280504381FDB2D54E013B89CD103063F 36558 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\D3868D3E6FEEE89984797B506F65B1B35CF6F3E7 2330 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\D3B6692EF05A485B459374B996D9D97AE0EFD618 1147 bytes File C:\Users\Studion\AppData\Local\Mozilla\Firefox\Profiles\5f898yp6.default\cache2\entries\30B2EC0940548E0884D874384002323AEBB122BF 1676 bytes ---- EOF - GMER 2.1 ----