GMER 2.2.19882 - http://www.gmer.net Rootkit scan 2016-05-16 19:43:02 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD75 rev.03.0 698,64GB Running: m6dmv558.exe; Driver: C:\Users\MGRK\AppData\Local\Temp\ffrciaow.sys ---- User code sections - GMER 2.2 ---- .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 000000004a3e0480 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 000000004a3e0470 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 000000004a3e0360 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 000000004a3e0490 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 000000004a3e03d0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 000000004a3e0310 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 000000004a3e03a0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 000000004a3e0380 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0xffffffffd2884490} .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 000000004a3e02d0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 000000004a3e02c0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 000000004a3e0300 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 000000004a3e03b0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 000000004a3e0440 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 000000004a3e03e0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 000000004a3e0220 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 000000004a3e04a0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 000000004a3e0390 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 000000004a3e02e0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 000000004a3e0340 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 000000004a3e0280 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 000000004a3e02a0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 000000004a3e03c0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 000000004a3e0320 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 000000004a3e0410 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 000000004a3e0230 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 000000004a3e03f0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 000000004a3e01d0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 000000004a3e0240 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 000000004a3e04b0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 000000004a3e04c0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 000000004a3e02f0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 000000004a3e0350 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 000000004a3e0290 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 000000004a3e02b0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 000000004a3e0370 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 000000004a3e0330 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 000000004a3e0460 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 000000004a3e0420 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 000000004a3e0250 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 000000004a3e0260 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 000000004a3e0400 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 000000004a3e01e0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 000000004a3e0200 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 000000004a3e01f0 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 000000004a3e0430 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 000000004a3e0450 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 000000004a3e0210 .text C:\Windows\system32\csrss.exe[692] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 000000004a3e0270 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 000000004a3e0480 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 000000004a3e0470 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 000000004a3e0360 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 000000004a3e0490 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 000000004a3e03d0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 000000004a3e0310 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 000000004a3e03a0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 000000004a3e0380 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0xffffffffd2884490} .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 000000004a3e02d0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 000000004a3e02c0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 000000004a3e0300 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 000000004a3e03b0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 000000004a3e0440 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 000000004a3e03e0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 000000004a3e0220 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 000000004a3e04a0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 000000004a3e0390 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 000000004a3e02e0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 000000004a3e0340 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 000000004a3e0280 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 000000004a3e02a0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 000000004a3e03c0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 000000004a3e0320 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 000000004a3e0410 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 000000004a3e0230 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 000000004a3e03f0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 000000004a3e01d0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 000000004a3e0240 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 000000004a3e04b0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 000000004a3e04c0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 000000004a3e02f0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 000000004a3e0350 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 000000004a3e0290 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 000000004a3e02b0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 000000004a3e0370 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 000000004a3e0330 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 000000004a3e0460 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 000000004a3e0420 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 000000004a3e0250 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 000000004a3e0260 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 000000004a3e0400 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 000000004a3e01e0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 000000004a3e0200 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 000000004a3e01f0 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 000000004a3e0430 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 000000004a3e0450 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 000000004a3e0210 .text C:\Windows\system32\csrss.exe[796] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 000000004a3e0270 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Windows\system32\services.exe[840] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Windows\system32\lsass.exe[856] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000000070480 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000000070470 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000000070360 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000000070490 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 00000000000703d0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000000070310 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 00000000000703a0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000000070380 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0xffffffff88514490} .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 00000000000702d0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 00000000000702c0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000000070300 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 00000000000703b0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000000070440 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 00000000000703e0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000000070220 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 00000000000704a0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000000070390 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 00000000000702e0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000000070340 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000000070280 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 00000000000702a0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 00000000000703c0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000000070320 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000000070410 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000000070230 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 00000000000703f0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 00000000000701d0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000000070240 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 00000000000704b0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 00000000000704c0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 00000000000702f0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000000070350 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000000070290 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 00000000000702b0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000000070370 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000000070330 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000000070460 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000000070420 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000000070250 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000000070260 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000000070400 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 00000000000701e0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000000070200 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 00000000000701f0 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000000070430 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000000070450 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000000070210 .text C:\Windows\system32\lsm.exe[864] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000000070270 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Windows\system32\winlogon.exe[964] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000000070480 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000000070470 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000000070360 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000000070490 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 00000000000703d0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000000070310 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 00000000000703a0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000000070380 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0xffffffff88514490} .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 00000000000702d0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 00000000000702c0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000000070300 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 00000000000703b0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000000070440 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 00000000000703e0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000000070220 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 00000000000704a0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000000070390 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 00000000000702e0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000000070340 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000000070280 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 00000000000702a0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 00000000000703c0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000000070320 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000000070410 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000000070230 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 00000000000703f0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 00000000000701d0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000000070240 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 00000000000704b0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 00000000000704c0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 00000000000702f0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000000070350 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000000070290 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 00000000000702b0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000000070370 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000000070330 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000000070460 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000000070420 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000000070250 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000000070260 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000000070400 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 00000000000701e0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000000070200 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 00000000000701f0 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000000070430 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000000070450 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000000070210 .text C:\Windows\system32\svchost.exe[1008] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000000070270 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Windows\system32\svchost.exe[684] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Windows\System32\svchost.exe[1076] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000000070480 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000000070470 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000000070360 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000000070490 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 00000000000703d0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000000070310 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 00000000000703a0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000000070380 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0xffffffff88514490} .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 00000000000702d0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 00000000000702c0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000000070300 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 00000000000703b0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000000070440 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 00000000000703e0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000000070220 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 00000000000704a0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000000070390 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 00000000000702e0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000000070340 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000000070280 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 00000000000702a0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 00000000000703c0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000000070320 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000000070410 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000000070230 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 00000000000703f0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 00000000000701d0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000000070240 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 00000000000704b0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 00000000000704c0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 00000000000702f0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000000070350 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000000070290 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 00000000000702b0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000000070370 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000000070330 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000000070460 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000000070420 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000000070250 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000000070260 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000000070400 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 00000000000701e0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000000070200 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 00000000000701f0 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000000070430 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000000070450 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000000070210 .text C:\Windows\System32\svchost.exe[1108] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000000070270 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Windows\system32\svchost.exe[1152] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Windows\system32\svchost.exe[1184] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Windows\system32\svchost.exe[1360] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Windows\system32\WLANExt.exe[1596] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefda3c750 5 bytes JMP 000007fefda20038 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefda49ac0 1 byte JMP 000007fefda200b8 .text C:\Windows\system32\Dwm.exe[2304] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 2 000007fefda49ac2 3 bytes {JMP 0xfffffffffffd65f8} .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Windows\Explorer.EXE[2332] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Windows\system32\taskhost.exe[2376] C:\Windows\system32\WINMM.dll!waveOutReset 000007fefbb2a38c 5 bytes JMP 000007fefda102b8 .text C:\Windows\system32\taskhost.exe[2376] C:\Windows\system32\WINMM.dll!waveOutPause 000007fefbb44b60 5 bytes JMP 000007fefda10238 .text C:\Windows\system32\taskhost.exe[2376] C:\Windows\system32\WINMM.dll!waveOutRestart 000007fefbb44ba0 5 bytes JMP 000007fefda101b8 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[3300] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Windows\system32\SearchIndexer.exe[3796] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe[4384] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[2300] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Windows\System32\svchost.exe[4652] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe[5676] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[5524] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000077038791 8 bytes [31, C0, C2, 04, 00, 90, 90, ...] .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Windows\system32\igfxpers.exe[5940] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Windows\System32\wscript.exe[5124] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExA 000007fefda3c750 5 bytes JMP 000007fefda20038 .text C:\Windows\System32\wscript.exe[5124] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 000007fefda49ac0 1 byte JMP 000007fefda200b8 .text C:\Windows\System32\wscript.exe[5124] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 2 000007fefda49ac2 3 bytes {JMP 0xfffffffffffd65f8} .text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[6728] C:\Windows\system32\WINMM.dll!waveOutReset 000007fefbb2a38c 5 bytes JMP 000007fefda202b8 .text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[6728] C:\Windows\system32\WINMM.dll!waveOutPause 000007fefbb44b60 5 bytes JMP 000007fefda20238 .text C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe[6728] C:\Windows\system32\WINMM.dll!waveOutRestart 000007fefbb44ba0 5 bytes JMP 000007fefda201b8 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort 0000000077b5bbe0 5 bytes JMP 0000000077cc0480 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject 0000000077b5bc30 5 bytes JMP 0000000077cc0470 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess 0000000077b5bd90 5 bytes JMP 0000000077cc0360 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx 0000000077b5bde0 5 bytes JMP 0000000077cc0490 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess 0000000077b5bdf0 5 bytes JMP 0000000077cc03d0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077b5bea0 5 bytes JMP 0000000077cc0310 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077b5bed0 5 bytes JMP 0000000077cc03a0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject 0000000077b5bef0 1 byte JMP 0000000077cc0380 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject + 2 0000000077b5bef2 3 bytes {JMP 0x164490} .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent 0000000077b5bf30 5 bytes JMP 0000000077cc02d0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent 0000000077b5bfb0 5 bytes JMP 0000000077cc02c0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection 0000000077b5bfd0 5 bytes JMP 0000000077cc0300 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread 0000000077b5c010 5 bytes JMP 0000000077cc03b0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtResumeThread 0000000077b5c050 5 bytes JMP 0000000077cc0440 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread 0000000077b5c060 5 bytes JMP 0000000077cc03e0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry 0000000077b5c1c0 5 bytes JMP 0000000077cc0220 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort 0000000077b5c380 5 bytes JMP 0000000077cc04a0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject 0000000077b5c3b0 5 bytes JMP 0000000077cc0390 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair 0000000077b5c490 5 bytes JMP 0000000077cc02e0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion 0000000077b5c4a0 5 bytes JMP 0000000077cc0340 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant 0000000077b5c500 5 bytes JMP 0000000077cc0280 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore 0000000077b5c590 5 bytes JMP 0000000077cc02a0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077b5c5b0 5 bytes JMP 0000000077cc03c0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer 0000000077b5c5c0 5 bytes JMP 0000000077cc0320 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess 0000000077b5c630 5 bytes JMP 0000000077cc0410 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry 0000000077b5c660 5 bytes JMP 0000000077cc0230 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077b5c800 5 bytes JMP 0000000077cc03f0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver 0000000077b5c920 5 bytes JMP 0000000077cc01d0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry 0000000077b5c9e0 5 bytes JMP 0000000077cc0240 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey 0000000077b5ca10 5 bytes JMP 0000000077cc04b0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys 0000000077b5ca20 5 bytes JMP 0000000077cc04c0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair 0000000077b5ca50 5 bytes JMP 0000000077cc02f0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion 0000000077b5ca60 5 bytes JMP 0000000077cc0350 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant 0000000077b5cac0 5 bytes JMP 0000000077cc0290 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore 0000000077b5cb10 5 bytes JMP 0000000077cc02b0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread 0000000077b5cb40 5 bytes JMP 0000000077cc0370 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer 0000000077b5cb50 5 bytes JMP 0000000077cc0330 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx 0000000077b5ce40 5 bytes JMP 0000000077cc0460 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtResumeProcess 0000000077b5cfa0 5 bytes JMP 0000000077cc0420 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder 0000000077b5d040 5 bytes JMP 0000000077cc0250 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions 0000000077b5d050 5 bytes JMP 0000000077cc0260 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077b5d060 5 bytes JMP 0000000077cc0400 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation 0000000077b5d220 5 bytes JMP 0000000077cc01e0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState 0000000077b5d230 5 bytes JMP 0000000077cc0200 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem 0000000077b5d2a0 5 bytes JMP 0000000077cc01f0 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess 0000000077b5d300 5 bytes JMP 0000000077cc0430 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread 0000000077b5d310 5 bytes JMP 0000000077cc0450 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl 0000000077b5d320 5 bytes JMP 0000000077cc0210 .text C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe[7108] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl 0000000077b5d400 5 bytes JMP 0000000077cc0270 .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000076d91401 2 bytes JMP 7705b263 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000076d91419 2 bytes JMP 7705b38e C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000076d91431 2 bytes JMP 770d90f1 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 0000000076d9144a 2 bytes CALL 770348ad C:\Windows\syswow64\kernel32.dll .text ... * 9 .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 0000000076d914dd 2 bytes JMP 770d89ea C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 0000000076d914f5 2 bytes JMP 770d8bc0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 0000000076d9150d 2 bytes JMP 770d88e0 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000076d91525 2 bytes JMP 770d8caa C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 0000000076d9153d 2 bytes JMP 7704fce8 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000076d91555 2 bytes JMP 77056937 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 0000000076d9156d 2 bytes JMP 770d91a9 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000076d91585 2 bytes JMP 770d8d0a C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 0000000076d9159d 2 bytes JMP 770d88a4 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 0000000076d915b5 2 bytes JMP 7704fd81 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 0000000076d915cd 2 bytes JMP 7705b324 C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 0000000076d916b2 2 bytes JMP 770d906c C:\Windows\syswow64\kernel32.dll .text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[2188] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 0000000076d916bd 2 bytes JMP 770d8839 C:\Windows\syswow64\kernel32.dll ? C:\Windows\system32\mssprxy.dll [2188] entry point in ".rdata" section 000000006f0b71e6 ---- Threads - GMER 2.2 ---- Thread C:\Windows\system32\svchost.exe [1360:2780] 000007fef73f5170 Thread C:\Windows\system32\svchost.exe [1360:5028] 000007feec9783d8 Thread C:\Windows\system32\svchost.exe [1360:5064] 000007feec9783d8 Thread C:\Windows\system32\svchost.exe [1360:5068] 000007feec9783d8 Thread C:\Windows\system32\svchost.exe [1360:5072] 000007feec9783d8 Thread C:\Windows\system32\svchost.exe [1360:4324] 000007feee8b3f1c Thread C:\Windows\system32\svchost.exe [1360:4328] 000007feef4c1a38 Thread C:\Windows\system32\svchost.exe [1360:4336] 000007feeed25388 Thread C:\Windows\system32\svchost.exe [1360:4344] 000007feee917738 Thread C:\Windows\system32\svchost.exe [1360:4368] 000007feeed11f90 Thread C:\Windows\system32\WLANExt.exe [1596:1632] 0000000075561dbc Thread C:\Windows\system32\WLANExt.exe [1596:1640] 000007fefa4c2760 Thread C:\Windows\system32\WLANExt.exe [1596:1648] 0000000075561dbc Thread C:\Windows\system32\WLANExt.exe [1596:1776] 000007fefa1e2f9c Thread C:\Windows\system32\WLANExt.exe [1596:1900] 000007fefa0b46e4 Thread C:\Windows\system32\WLANExt.exe [1596:1904] 000007fefa0b4700 Thread C:\Windows\system32\WLANExt.exe [1596:1908] 000007fefa0b46c8 Thread C:\Windows\system32\WLANExt.exe [1596:1912] 000007fefa1e2f9c Thread C:\Windows\system32\svchost.exe [6604:5168] 000007fee7c0f130 Thread C:\Windows\system32\svchost.exe [6604:6624] 000007fee7c04734 Thread C:\Windows\system32\svchost.exe [6604:2292] 000007fee7c04734 Thread C:\Windows\System32\svchost.exe [5420:5096] 000007fee48f9688 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [6240:6520] 000007fefb0e2af4 Thread C:\Program Files\Windows Media Player\wmpnetwk.exe [6240:1116] 000007fee4b58f70 ---- Registry - GMER 2.2 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{C1B88256-CB59-430C-8238-D52AC70CBF5A}\Connection@Name isatap.{F2032006-5650-4D90-877F-A8D249030B53} Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Bind \Device\{C1B88256-CB59-430C-8238-D52AC70CBF5A}?\Device\{1A185750-7D28-4AF1-A3BB-5C2CFA956E4E}? Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Route "{C1B88256-CB59-430C-8238-D52AC70CBF5A}"?"{1A185750-7D28-4AF1-A3BB-5C2CFA956E4E}"? Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export \Device\TCPIP6TUNNEL_{C1B88256-CB59-430C-8238-D52AC70CBF5A}?\Device\TCPIP6TUNNEL_{1A185750-7D28-4AF1-A3BB-5C2CFA956E4E}? Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\9cb70dcf6769 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\9cb70dcf6769@e66846ca2027 0xC7 0xFC 0x8F 0x96 ... Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{C1B88256-CB59-430C-8238-D52AC70CBF5A}@InterfaceName isatap.{F2032006-5650-4D90-877F-A8D249030B53} Reg HKLM\SYSTEM\CurrentControlSet\services\iphlpsvc\Parameters\Isatap\{C1B88256-CB59-430C-8238-D52AC70CBF5A}@ReusableType 0 Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\9cb70dcf6769 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\9cb70dcf6769@e66846ca2027 0xC7 0xFC 0x8F 0x96 ... ---- Files - GMER 2.2 ---- File C:\ProgramData\AVAST Software\Avast\spool\suspic\{C33D58FA-2007-4B8B-A357-276EC314C309}.suspic 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\14ED496D453F180AA63884F49CE79C0F5AD6A149 4137 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\101E61E061FEAC97F72DB9524542AF4F53064FEB 4075 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\306975483C5531DA49E725D8BD364F274830E063 4241 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\34240D61A057643C82EC0DBF880ACE4EA32C34C1 4162 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DE1785624FD9FF29FB3F0E460352340E7A8A78EC 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\36E906A1E94F2B586831ACC84D1126CD7AD276FE 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FB23F2F8A109C7DF22F338C87ED16F0F1AB01292 1954605 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\99C6EF937E03A11474F101E9429811A20D4A65C4 4198 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E24778443E487B213552911D3E2C3789AF03CC5C 2334 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A5590B15B243227AD5C5D7CDCBA19453F0DE10A9 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9A9DAEF871A9AB2464996F5B672630643C183D84 2413 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C1323A129F06C816B04F44F97DE766E760934CB4 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\310A140E220FE90523C2B629C498B239B4CF6D9E 4906 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\27A8D412550C4069D5FFC2B5D4D0E8D6E7E5B91E 349009 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\71A94324B9ABF90EBD4E831CE22BBD3380AD9791 23796 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8E28DE85758352438CFC586D8922818446374BD8 335137 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\26C2C975025495ADCC2268E369FC99F72978F050 12554 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0F970AE833DF2F55F3527AD578001787209EC15D 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\66C011101B43226731AABC58D14BC2C885C5EFB5 4872 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D4F936C7B7E2BA009EE7AE0BBC954264BC697E28 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E60705BB1FB23EB8009BFA7F3CE27B2574D39C7C 8591 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6833034EB343BF9CFD6DE8C961F4846B9529261D 2521 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C82B14B0E0E73616AFE4144DAA2A902285E034AA 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F483260E0E50EB4C126E3413BF0D9E1D17DE346B 1540809 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C1ADB2BC91971D6EFF80A17FE6B5BA2F5077C3A7 1562510 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E48B2AFC9471DB6A7CC23AED8FC8E883FC6B1C28 347672 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F23C01FC228B00341D7D8E8BECD2679DA9157614 362235 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6595CBA69F197B6A9CB060381B31A9E2FC9ADE1B 1635 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0F0027C9CDB53A3E985ABC743B0A57808F23B427 2243 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9D9FF974025441B7CBE2CBE1EF3A324B91B9E861 5049 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FB3AD1734E08B44D56DDF64ED0BF59BCD92937A5 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C9F1C077DF1BEB001A4743B36100D3AC490AEAA2 1974533 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\814D2D5C856C7E3124875D28059CA8E20965D283 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\52D25AEEC3394E9B42CC135FECA5F9CB2FAE1177 1561319 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\950C4E7F0E525D863262C8074259EE66376ECFFE 53712 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E2AF27DF42BF889F0FF6A28B195CE1B46B265D72 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\055E194A5CA5DD3964E81C50C5E1F5EA22FD70D0 6094 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7D01E0811BC3A4E0D8FBEEEB734F4675E5AF3DCE 1040 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4C7C84AB2D82D63C30CBE50A1F2528521B5A4021 2043992 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\40417D86EC8F9C4A4BB4BD191B74FBBC299AD7E4 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\404BBF31A861AA3A609F7A0AAC912BA7710DFDE4 26619 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B1A2FB3CBDE8CCF2B2409FD5DDD9658359EB91A0 19868 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4A4D6967C34EEDED02FBCA312E0976777B022205 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\163357FB1E12F2B9289D4C8A5D228A95174E52BD 1007672 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\73BFECC01EAA80278D0E4CA426C025BD2928807E 2351 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F88A3465F9C4F807D557A066A678B6023EA76918 92832 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EBFD6E7F621BF3D23F9FA5436FB50F64D584C0D4 1462 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FF9E40F6346E81DAFFF3CFDB0A34E8CCF4185A9F 1772 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FFA2E33F712CFD52A98D27434B10813419850C33 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\367F6842BC40AD9B7ED2E3B9D4CCB21F0742AA29 3547 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4AEBCAFEFBC8D405E1345C1D844B215F83C7EED6 7857 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E6679B3C6B72A9F70EC2964376DBC39451603AFF 6611 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A17E6CB806E9026A8DCCD6C1EE4E4FFE9EC41EA4 3743 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0C9D16503EB891A94E3DBFE511E57FAA7FF260E3 8338 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\481108F08AFD5E7AA2F37A89BD2290B330AC7BAA 401 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8E53FB897C51A4021663E8D3C4E79B26E6985097 129192 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\BA0E7E3123644AE35027483422CEA8FCE07DDC91 967 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\61755E729B5F86D8C458C684728C7262D03B066D 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\BEA2C920C33B8AF43A4BFA023DF3D80542CA4F78 347181 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\474FE167DE9261806A458655C6C5B468B14B4F67 7361 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4AA0FB2EB95B99F2E3F41351BD0885D2EFD07FB8 2054 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2A4D0D8A2DF2C0377B823973C4AEE5F39CD54A89 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2A546049DB4CEABFDACCFE598AB2D5495DF66222 972178 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3038CC99E33EC2070AADB347D019355785B53DEF 3354 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FEDCAF759FD425E773E5FC45C30697B20FB6CF34 3743 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E8202069B9D15B1510412D374969137AD7C58AA7 26242 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\457B915561A542AB182AE1463D40EEFBFEA7258F 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FCC90EE06F4D399CBBD3D0AD8C5CA3252912BF74 1643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\AEB6291357D543E8A948A952FF0B55DCAA84CC30 2017 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7764CF5330A7880529E139D07C407C2EF2BE11BB 2453 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2D0615BD0273C9766BC1F61FF2CC0487AAB999C1 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\75D14FF245BEBC0E712C170ABC9364F8B4FED45C 3622 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7BE527D21EFC1986535E05B68734D3CCCFA58878 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\80EF8D0A0FF93BD5C5A32C78505E98197555103A 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\67BBA7B8B5129F669B86C320753211FAA41108DB 584 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EFCE1DCF8F4F9F578EA1E24C65E47CE9EEFA3687 2074 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EFD56963718332063067E7EA79D8D95912EAF4E7 2713 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\202206C4A97413B00B4AD4873012E871D43709EC 4018 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\162138CA95254589CBFDAF57C1536670EB0C4AB7 1550232 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C3FF782B94C864E92D59452BDD286E3397B7F2F7 2717 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\50DE8E24FAA9E6D145575D9208299D6968463CA5 2605 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\30B44383ABDFEC8813B2A7C98FC8CFB58C32264C 12366 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A65C20217FC004DEFDEEC0C5177AD7DBEFE36274 162070 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5E436B8A13579EF6F04EC80757F33B42E4B9072B 465 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\75851F8C3AA368AFCA17B47F40C60062DD02051A 29551 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\95388E9038E492AE496F14F25925B40D870A2D2F 4131 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9547CEA66C5DDBCE4F8E47B05129D0A0BE877E3F 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0019452153167DCBC4C5B775E41FABC42577A6CD 4748 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\BE2E1845612D295B1E0623BFFD74DF93C25633F2 321957 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\BE3311D8F3D61B0A5B15AC6642B6243AE36B9C28 1056 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\19EEE9919BD56AE2333B5B32EBBBC95D7A4878A6 7182 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2A2848A7356F283AE8089C13B80F7232711D25C9 4194 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1A9D0CB3E1F222461A55A3BA8AF7B91978CA5FAA 56593 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1B30BB9D4D76CAAB41F167F06D54EF797009D916 4151 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\59106E92A80A37EEF2990FDD6E73398F41A09FDA 978 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2F267056857B8A5C7882925628BA6FA973D1F526 1890 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A0C588379C56326CA5FB4DCFB32F7388AE43017A 4439 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\393A4EE4FDE94BBE2DA921DEADB6FFA0394A5419 15912 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D2D2AA5324FA4E347A97F39409103AC6A0BB453C 1230 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A601D627002FCF85095F904468DAC20F78598AF1 6779 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1F1EB316E387935DF7B8E7E43BE77546229C5909 3986 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1F293149D35CCB3F2A8B691F44F5CB4F22D03154 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1F3323110E7BF099864FB2D2DF9A876C95F2C074 4196 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\BBD404E76010825C384F344343332D7493183953 30686 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\73079F37389D2C8D73CD481931EB3D684761F9EC 3952 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D844FE654937975A2FC5AA82B0B5BEAB56798E1B 1270 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D845B253C0540C9B717CF37DFB88BB79329AAF41 3561 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\54CB24F2C2CA836658856FE83600C3AA81CBB4E6 474680 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F26E795D3FF6529FCE2FD039235537CA798C31B0 19903 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0BE3DDBACBBBB6C3DF7A354F56ECCAE5B3617997 996 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EAA18F0F5696F2A46D4FF22F30587D948E782158 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\75026131CA5CB6BCF200C6BA25730944DB799352 4667 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\85CED1C6FBADD07119611A5488DA517C608D13A8 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\402373FB925A566B3BAC0F94501CDE1BB5A16927 2443 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\850AD71212EE99B6CA568A8E1E944AF9F0F8AC2A 7459 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\260C9131B167316675937C45D64A945180C4AE78 12964 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\260FCFB68E94816584BB86CF78D07B2F42A7F9BD 1557408 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B65959479BAC4B378BBFD5C1175E50D8FF7A918E 4796 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\68E941C2519662B7FF38439356EA151CFD103B88 14130 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1AD2A13F62140DD71699D5BABD5E61541A47E4B5 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\12CA667FD8CCEBD864BED71F7B7DA2C8D9DA43D1 4183 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\42303E19A4AC639C65B8669A165DD592D234494B 2773 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\209F8A0A0D4B515F0E1EC37D7DA81C2F9E78C165 616 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D1E8C4F6ABF6D88BF9AF6733BD4816217FE32992 8874 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A6A2C0825D67179A393F0495A6ADF731B71D22C0 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A3E08558D3256AE071B9579CD4B828D4F9DB98B9 3547 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\BF5812F492F37EC3D1FFE768A3BB9B952869667F 4145 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6E8913E2F69D09BBE8BB021414F518F03A1E5886 1510 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\AB388ED728CB85F4E5905DFA313DFFCA0804FD5C 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0526CB5A0BECC13C2CBAD7C838CAE5D0D59AA051 33881 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\612AF933655D5F27430B5A8EE1F821726A4FB9A2 1627 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\613D2393BDDF77970D07828FC0E1FF9BD0CD625C 1765 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E25E1B5F6A6890BD47A06BDCCB227B2671117E4F 16001 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\70820DD7A61248ED5CDE83CC05BD11BD6AB5CF9D 4184 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\452F2D4F659438B73F71C5AE379625F6E045B5D6 17165 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\31DDC6D9A28A8E2597C62C6E0DF5EF435CF3B3CE 5666 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6361797FD9E31C8888FE1F94FDE7E7F70CEF0D3E 3561 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\468C4C90BCD3DC35A3BE26714D2360394C52D9DE 4816 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E3568C02ED1062521FEF7E4A18E0FFA4B8AF871C 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9BE2107D5A4D06789F0C2E6B57C3C4A540105A13 3671 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CA5D4F8555BC3758333684FE875A806ECEFC7E48 5014 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E5A3A8687AFD8B37406F36DDCB74FFCED19A9AD4 885 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\ADD1C1D34DA6B404CE2E92799CFD2D6A0176156D 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\63AE3DC4D32AC993740DD8A384F21C4513A8470D 16650 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A74E5CE0CD6862F2B9FDD20EE93A5AFDCC5B52C7 1599 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\927777B1CAAFD3575A8C2995D2F55116E4A939B7 42006 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E6C8FBBC3A67599CF31E9DECB1CBA4A6FE42C82C 5427 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D21C9A157B905CD2CA7695106004E870218D628E 1716 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\56EDF79A94F177A8AFDF7FF6ADFC89C7A9F07E37 5193 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\819075AB9A52A69C3C9193FD184214434437DF48 21518 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\08FD13E0E6F77584F8A485B6688EBFDACCD2938E 2123 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EA338620908FDE740DD7ACCD6C870EAAD751BB88 5206 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A89752FF6EDAB8FFB0A6BAFF38B084282773D981 15127 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\36A5F40AC91DF2465DC57CA0931795F48D99A220 4286 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7016BE9B941EACCA2E8B81C4756575E9C5C92A51 2531 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\95BCF5984CA8631B431CE53F31CDB1B7C4DB6D79 4179 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D68F3F35F4B44A93254AA4F4E70C1A9F3406C1FF 5258 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D6900B51838C25D3A8E14F141BB72A1120A7939C 1366 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CD473311E964EB8E539D9C4DDA3B8F88496FA29C 3165 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E1F03F88E2DCE084C358334CB7DA81C31F62CC57 26106 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F652B83B11C2BA9574F0900C9563C1FEFB40DC7C 107763 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DB8FF4C4F7409206598983E5CA915798EA4735BC 139557 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4339991F091D39894152CC245F909451A3BF56E4 5033 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\327F945DE942A8181DD32A25938AF818DC7D6EEE 2221 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1EA968A4F0580ADBB09BF789A130049892134B21 1265 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1EAE75EA1238BC37C9735DB81ADE286F218EC977 3547 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\94EE9A3098B3353B59BC03B9EC8E4E3ECE483094 4202 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\567F7B41269D528DB87CBB766607C8AD0FEBD592 534 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4111D55424F7E0EFF4410802DAFCEEAA98D94277 505 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DB3E256B0484835C165CD4E2116A7FBF0AEBB2E0 2309 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\033F1DB2CC53A8C2EF43FCE1FEBF47A04B33DABE 676 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C840EC6E9F45AEEE0A51C1556BC1237D7CFED944 2224 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CFF15CA44D8C7EF0F30D9B55DF8E72C1645F2CA3 152812 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F1A876FC17705023AFD2452DFAA01EF96BCDD4DB 11799 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\21105788E5075F394A7F4515F1E335305EFDBEEC 4003 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D191BE9B038089D0EE9CE9B377BD51ADD8BAEDC9 4214 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2833777B5CBB675D68CDF292DD1D521C1417394B 17439 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0F689106CB1A4BCFF9E68429751EEE8F5D252452 4232 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6ADCC067F8F778939A70E23282A584C4E11ABFF9 133080 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2F4B98BD1A7A9353AF9684EC781848746D7DF44A 5359 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0391728FCBE28EC7D3907CB53D5495A67F9237CA 534 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\039CA531156A666910963F12626B340B60718A9D 1725 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CE58C5664E55D5FCB56503F5C79CCB89548EA7D0 14889 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0303E5D0C6F64A23B5131F76B02192DA8BD944AA 1555836 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7B3845B01EC122295283E7F3F3334252A0B9845F 5046 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\32B27EE3118C7760E90B2F1D05F43A2801665DBC 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\85B2D9C964F6731B77727D416DC2A5F06E97CD21 4653 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DBD41D9D53F3CC3BE617E94799BD51A7B83E051E 10743 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8B4D528323B29687868330FF3469C17E7BD1F701 15345 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D921538083063D9A75477C7E7B00FE23269AC9D5 158453 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7CD3F277BF13023B00A15DF7970AB86B838737FC 2005 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C43CC1104D5F8DBFFF609A4B44E3B17364ADE205 42539 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\668CD6FF29260642F8D399A9444DEA9F112DFFF1 32593 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\669108DDA403D4727BB751471723B8FF6709ED36 440 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6697FE64073474759E9AD97ECF1BDB36CFCEB24F 3415 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DF5E90179E0405E37B1D930211082739A06C9667 5341 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\37BE4D48199608F5A9F1BDABD3C274258F2C98EF 4142 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6D14112DA909D60836291149BD04FB5FF409878F 30101 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F0611B64D2EB19AFE004A2EFCD199534871BBAA3 3775 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F3C99D1BA3AFD72C86FDEA6EB15DCE839FFF852F 4104 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E290848C17446C16F545916A50C2AF868EDD8085 978 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\27D8890B2C0FE2888C51F01DC012801232A4829D 465 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E7D03BC684B40EBCCF249F0668644FEABAE88A6E 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F59E9D8FCF365B6F7A63B8425715B5D839A02FB7 13428 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F5A12653819E7BC963BE05B4C7AA59238DF28798 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\795B2C151BFDA3AAE79B1BA30688DD35F46071EF 62080 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3F569F33DE35BC1DCF1C7F902BCB85FCC9453872 99679 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FA6C30927946F1ED5AAE1CD17ABD2A59BD2ABA69 4215 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9B03E99C7F2ED81F27348CE917DE43C4B084CEA6 7782 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\60C4B84B81ED950653F547652752D4637FF2BFBC 1228 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\34D02F2DD7B890C11565752551ABFFC00B8599B2 978 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E003920955ADA5A3C52523140AD3766963C52D08 3759 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\227D18004D431C2EC42716F3A392955E2647F889 187805 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A7A63CCBEE4C2D8FA4F949418FC69B27D04176D6 33013 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\64652696AC1C1CFC45E872F2D6AD0E763F44B800 120179 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B4A00571EECB236F16E3C925EBBDD6F9CD76417F 62224 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\17688BAA8FB7D94A2AD66EA8E7E41F51CAB63F99 32131 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9795004FD6D371E918D6E35D09F0B90ADA40AD2A 505 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A11923A5AC268177E7DCAB42B96686A2E0467B4D 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9F0BCBBD92A0B599395FAA20F55E3E3F700F2C57 1729 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9F191F8E18448FAC4A4B1AEB5145BABB030AFAEC 465 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9A952EA6452A211C2C51C5A5BFC77E8BDDD052BC 842030 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F2D8474BB42B6729C0B0FDAA18D53762C16B292B 6673 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4F4EFCF325BF5BC9135A1F2B79990774DBDA0FE7 2258 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D34C323B23C5CCA79DC12803709A05855671B1D1 14201 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A6ED711453D27F72F6404FC7089EFACDC244EC06 20409 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A6F645B69225440348BECD0ADB2615022B4B2948 1560434 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FCAA8C62231D440DDF8C811A08F147318A18B882 18424 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FCB500BF0FD82A69D1716B3652590C7299A266A8 1662 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4973082E09A900B8A02A851FD283A8A5AE180BE7 1551720 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2C7B5DDD5CEDD2CA8DDB8FBD77DECD064933F735 40520 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8F616F9D6410594F7CF97A6F08BBE2A30A3EC2E3 2887 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8F6DF123006A3223A7D1DE08223D5B3910CF6B86 2424 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\169C99D36CFD892D1C5F173813E30A549A9FF15D 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E4577185939B79E16E55171358774ED6AD776506 27176 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6DE39B0B5D4168A4DB4D6412055B6DA439B8909D 1015 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CA263E904F8E8E50F4164BE19CB3505EB711EC8F 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CA2F20D989528D6C64D5BC72C88B2E606147D1E5 1557769 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5658CA03ED66F6D9D8343E29F10B658022CE5B47 20984 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\54A34C1A634CF160BB989BC4109A2ADD309B8DB3 3543 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1D5FC44436943C1BCF7D6FB33AAE937BB63C4F4D 1459 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A804431F93CFA48F396D075A096014F995B5DE61 1555921 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E058DD8023AFB2CDFD4EA123283F34910B75B8BC 21099 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\34ABB86741F4BED3632242342B7B77CBD3CF56D7 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\34AED2651C6DD09346140058BF11425DBE7F5512 6607 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\34B55211D5070719805EBE95070517D8011804CD 5026 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0198143B1C68E8C13891485ECEAFD602860ED351 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5FA82D38220A7552623A9D544D5AADF9254E6FCF 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\08B936CAC750E0384FB81A4C1DA4AD372D9E6730 83501 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\08BB52117052ABF64B9F7385A514E380737053F1 465 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B1C5F5E5590E6CB6813947D26486A39179DF65AB 4276 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4C96374999A597DD7F1F6F7DBBC992875342B674 1575006 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4C984FF3E175785AFF4D92D3F8D67F0863CA543C 3462 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9A67312CABDA2210A5932CF488D70910CA1F7405 7237 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\ADC54018A237B4B3DC84D05EDB65BDEC60B44B04 3668 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7E536EDF45629083FAD183260C8FE9F63881388D 1554379 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CF13B980459E30485539904EA7CD797F0B9E5214 50265 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FDD3884A14706D0A787271811D5DB63C3FDF12CE 17441 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9F46CBFB8334364D9AFCB6C39AB7F1B4C1D3271B 1460 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0ACF9AE6E191B9939FA7FD4CC13F21C7C03DA1CC 307 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0ADBC68AB7192E7422199C52CEE33B7D95FDA725 18127 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C2A33AC8328EB264FFB8D29E94200E327F58DF81 4091 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9C05AEFD260E4A8A02FD10DAA1BDDC29A38E7C6C 5910 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9C0941ECFB90C102BFCD7D4FF3BED9C04A8EB3D1 70252 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\00DC0AFD65CAA237E7B031E381B2080C46C5E8AF 16202 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0CC2E4E4CB8C29BBDBD6E84128355AB1971B4E16 1605 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1359E51D32045FB71AD11DFC229210BC85552C32 35198 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D5778C604E2EBE36267323BE57975263B1DCA6AB 114751 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\99423933CA8816772D31B8CED455857973F82FCA 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F71741EF8D06DAB39825ED194C2F73928E5DE7F1 14677 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EDB95EC5B1F26AA9FC83336CF70BE2C2E701CCCC 1553763 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\29873BC7A8711A6140E9B5D2F9B7601250865678 11683 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2988546A0D7738994402CEF265F0380F950972F3 40591 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D11F068B78A277D000A8B4ADBFD6EB5058FAF4ED 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E130C2E789E6EE84EB1D4A9F3AD4BEDF951A81AC 4095 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9B61402EBF93ABE6717948F43ED94CC142F8B70B 4124 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C56B55ABF81C43C701C5134D81FAD44F807B5584 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0FC54A0214565EEF0232BC3A8ADB135DAE62DECF 758333 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F407E00A403331EDEB8816AB069C271AB3CC0A59 1561804 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0311ABBD11838FB47AE1B61038420E67C7856C08 6403 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3463CD5B7E6519E88F40561D902A245EF79F7624 42395 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\34688C5FA4F61E623E26E4D76EA727E3C6843E6D 14314 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\346B0CD7053B474C7FB631DE7078FD5F4F10317D 26280 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\01B21A49527390FBF7962C11213B4B9013E15FC3 2428 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CD9A5BC162D3FEDA880780330F1DE7160952F32F 5304 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CD9DA120E854D793DB071CF8ED55DC3962B5BC3B 8528 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\004FAD093E128C4C53CF3D8222667BFE470073F4 1565064 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\00531F1E7E85CB350B551E494A9106DB37F8AE2B 687 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\76DAA7398EC06D23F9F525A7B7B267446180614D 2914 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6BD9B77616366062E76D1AC6C5597A4A4540D1BB 84398 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6BDADD1DA07B0FD717C3B65198692C944CDAE722 2548 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F9933C37CA92948F6AA5A01B93A875D1D775096F 2837 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1952A9A1E993BE52C00311942FED441D85F29FC5 5016 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\22EFD80244776EAEEA79A13371D48636448CEB2D 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\15BDF3A093599385BCFED7E925FE5B7905C0BFF6 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8D7BA9F33820CC9DF6D7D82A31C9979C4AEFE9D1 9910 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4F9E9052D5E27E0EC09C1A6944D2B0E0FB851720 4354 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4FAAFFEEB909E5A324A523B333B8CCF57B3EFFE8 2579 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B85BF90B83D4A311F65FD51EFDC148D44A55A2AC 1553055 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C36BF8ED8F25B69DD68EB2EFC4DDBCB92D9A4CE8 2224 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9BC6F67240E25D4CE255AF3864F532090AF0DD64 10429 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F376D1D8247A09568D30EFFCBDB407C7DB4F8532 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C322090B922E7B8317683832D529C120090A7A2F 799 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C88D216135EE582FAD7E882A64B91AEF78BDA897 911 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B0E244F8BFC108EB5E3276AED68EF8B73AF41B5F 13562 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A6BF2C4008C7F84603374FF209F5233132AAA1F1 10638 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A6C4D47265F75B64EF8299F1C8BE04FD523FFD5B 18978 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2BA1BC98778972D81D61674228725FE69FA30851 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\04B41920FD3B012368E99553BC0F68DE7E241407 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9570EC4F4658BE125E2569A9C7D422D14EB72803 1562022 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EE689098237A2B0BCEEDC7B9A1AF744D350EA340 3775 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\25E9D829DFA8C29CED380BB9ED8DF273EF031EF2 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5E2AD291C9E6B2D61A7FDA990A2E12F742D605F4 1002 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9A1FD142B2680A3D81DE362A844F0EF5436B7AEA 449735 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\86D2EE31EA58030E283057404EEBC6742048FC23 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A32A6262C2E59D035D5F65CAA3C6DFF96413C9E3 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EDE15CE47D4408A33B76BB4D4C4DCBA5DBF63BA6 4405 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F496F2B9D549666FE6B3325961CE8B7FB9B4AB06 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F4972759E8AC2ADC3DBEC5F75FF1A3ACDC9A5E04 3712 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F5FBCF1F3E9F5035A47DA29296031AE1F32A7CA0 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\12B69B907A4F7BF1CA5B6EA2236C2F72EE325396 112404 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\12B91BDEB6B0793E4D5C1EB1BD244E5E1B7F9E63 4191 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\31580D7EEB4D87C0D610C8626F5D3F3222CA6580 61008 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2180825CC1E1163CF5B979A52EACF8179763EC40 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\21858F7F8833F4193B2882E99C6757BEB658DA67 7242 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0EED72AACF5DB9367D3705AA8B373EDC24851BC1 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9910E5D7573E5C4CFB1F4FB7D9F4BF9264FE480F 505 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3B4440E9C1F8C6C19DF3E746F8CE4288AF580B06 3857 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\27E78AB005F925D2B696B34ACAB2E73F2E175F7D 4184 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6949174F05DC6905DCDDF0DEFFD6CDD6AD7B3DBD 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A7C41AE46D228F421730ED28FBAA60A336ADC6EB 3992 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\76629659A11C477801B8980153C8150F54362B46 3123 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\65E4CEF1F4197069BA1E0A13DA93E986F6DE1BD3 1199 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\BAFEAEF615DEC2814D4D5DE072F16567234577A0 1831 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\BB02C11E37E4B7923EAFF13AB437F15C875520FA 1422 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B15F8D4F8AF2B3199C5F250B2EFEF003C655CC65 1548902 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8A74D07826DC10E8464A4375AC5711393BA0D271 584 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8DBC738E59E1FE0FE0E94B7D274036086103A0BB 4171 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7C22F562E8BD84604E34ED5D0759A1836B50AD43 328610 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A41CF591466CCF57D818B0965238E8F888BC1F34 4146 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A41E03BC0CE301947825E4AC1CC610B5A03C2D11 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\75E223ED7FB5958E59779DF4E55507C4E03649D6 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\87EE3403AE3585A194FEC120CA1A038A44A8F155 1568 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\749ADE03CC560ADCA576B1A901654CC0743E8AA7 1686 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\BD05BD1E631D9B9F37C8794999F110C28EB10E17 13284 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2E7AC930062CFC40B62B8F5D139C853FEBEF0E78 22671 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\98A8ADCB1843667470F696D84DF01047D751AF28 9319 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E59AAAE0AB439EA885C6717EE5A2EC24A6208B45 1021 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5B0A8D8EEC0AF69A3A8EFDABD2A8F078D3E53293 1460 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A5A812C95412FF64E7540BAC93E02E3123B29A1D 1220 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0DE278FBA1E64E7DDD16CC60FC4127CDCD52BCAF 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4415694AC9879ADE390D131B73271ECB0446FD51 2149 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\71EC179C982F32DBA6949FD2306F19FD18C0D84E 3696 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\76BD6700F9DE2A4B47818B3D1FBF73020994EE29 1558035 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6974C91A4914D02082C647C55A565CAE2D4FA2F2 84776 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DDF8880928C07080B6F66E273386542DED737C8B 3718 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\833DE183503E19841DE2A663912B4BB86BD4CAFD 6789 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0CFEC83A4F7984F7ADD8870DB7F933C09B86C824 5496 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D1EFC86B75AB245A72AB127B87E8D48630A02AE0 4502 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\13E412460ECC653EE82DACA7BDC333282FD490DF 2890 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7267F2395580BBC0FA27F406FF3F5308C5627929 3626 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F227B9B4A5FEAAAD9A4DA1EC29512C452F89347A 1234 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CE9FE372930B266FE0FEA605DF0CD93114ABED60 1758 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4544AFF169882B91AF04EEB8271F5D94D4FC0BBE 3335 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0C50D1A8C058E6677ED3A57DD3E7A1F4A92411A4 1366 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FBAC68C5C5E32CFCD6CD9FD8556B94B580889B29 1002 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8D8FCD4AC8EB9E3E167F08BC54B71DBCFE727663 1460 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\09F131A32D531B168533744693D0E06DB8D27FFE 2952 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A36F73EB456C37A4F4AB4EF0A8C367CE05E5DDDE 96896 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8E5E13958E415078024C779AC02208E36D8366AD 4171 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8E65E2816C4C794EE238855A1CEE6B0C2602A3CE 1553373 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\632A5FAA0165C681941B89086F91CDD775B651DC 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\633592E9C318F11DDD9113BC79D899D5F4A2D2C6 1460 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5E67E9907790098D40CC3233A035366A5956C01A 13191 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\02B9E72826D3F36838A2B7A871DF0215CDBA080F 5568 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FE0985A6591ED897A5E3E8D3701CD32960684494 4057 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\AA7CC6F7161EA8798C51A6293B45B4C916812524 2950 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6F6BFF219843ED1F1529327D671E281CC66231EC 6165 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D6A02333A861B2768D96D51F6C7FF89952F87F05 7403 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4323703D95EB779FC27CA5C55B4308B48FDCF7A3 4163 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4326F22C4C8B09C666356FDADCE7699794B51818 8318 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FF19C16CABDC36A7C038A2DF51BFA8C112EB7F6B 1556128 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\023795F875728F5D476625E949704A11CC2FAD7D 2765 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5A90D7DB9F877440A8EDB8D4AA23357DDC54127E 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3958F7250741573C9ACD8838ABB0EA73EBA247D7 48119 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D1ABC7E3199ADB0CF1EC960B21C0156235417FA2 7415 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8CBBAE8DEC913AAFF625669DAF32CA3562052D23 5865 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\542FF329562B58198812651D96D9F2C581132146 2070 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B1DA376507DC2AC037A9C327A70AC679013DA5F5 1002 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\831A51B62947EF82B3148E1669FA04B33061629C 41206 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\67FF073439FA67D10BF8E4E79039A013FD821EEB 3694 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D4140F2E4DD225624373A59DA2B748B665BA2524 20267 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6C0FCD5751062177E91A6F9308BBCF39ADFC9BE7 128870 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E8234127E7A5279D54914F02E8B2D1609C12D5D2 4419 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F6626B885FDD21891874372773C68B7AC3885407 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0A357DD0FB5C1E492B3F500BEF6009139CCBB037 307185 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E6837D30F619B3228C09F80EB30AAE65A1D42DA3 10092 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FF53B23147FE4E8233F01BEC82DF070ADD8146B2 2651 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7327D4341ADA0F947F88B0F978E724722C731563 1564262 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B099DCC3DA8291E5D069DC05FA5D97DC225B704A 5235 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2F040F3C14177DE4E1DE7C44BBBC83CB2D6E8350 6549 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0813A0072D6EDADBE8A28BA18EFC9C597187034B 505 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F86505D46C45C7C8AEA3CDF6C736B2B992AEDB5F 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F86E5EF19E83CBB0816A5A68FF8322924A765E46 53822 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3E224F9457AF53FB4794D5CEA1E4CB06CB6AFC12 1366 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3E27E611FD5A375B4F55495C553567DFD58FC272 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3E2AB461E1A31CC46BAB31104D91C37224F5920D 2131 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3C33F2F639C90337FB2A361449A0088339110D26 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3C35A09CF4CD0ED01599C9DE7D4A90AD1D4A0CBD 3689 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F317D3E77495D0AC884234DC7C7694D1D1ED4B9C 56964 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0E8476DF13B522400B6E4450216572554BCE7D2A 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0E84F09A67A89772A565351BFB988E94A43E761A 1599 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\50F6DEE0AB0A649824F76BFE60AFE6856756F614 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1387B576B3493A4430533E88D9F6B77D474EA99C 29593 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\016C55F2DE6F3BA3AF68E282A8FE90C5AE9B6A7E 1340 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4C652A5C9FD3B919219FFCF036D59996668DF8A7 9342 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4C6F5371574294758B7C21E20D1D2429D7983F39 12104 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\341C37A592D383D33C62646C91F5A9C72B8CD716 63184 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\341CDE7463E5CE4B39754E3F7DB96E6BDC9825CD 1751443 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D78C216F8C279450991241CA65A23F88FF82B916 4214 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\06A17639055412FA5A8E72BAEBE748BAC75078C8 4184 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\ABC8D30CC56C25A38EB5431169345830DE858B97 51789 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\ABD3CBA997ED9CE74674B2EF7761466518C1FC03 3554 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\ABDA3810C341E50BE9F6F08F11D847DA1E5E4594 4205 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DF34FD18CD6F6034FC9A2219E888E8AB043D0CAF 3555 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CE18229313942025142A8E2BCF50A4F43695BCEE 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EB5E8FF8A8F54003F2873225454E8E62589ACA79 10819 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\61AC32A53E590A9743817F6BE97D658A1BE7B6D4 45161 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8068A56BA64F638E89C9BF6DDC92A36835CB4E3B 55298 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F4B7D1E1524A7B9B0A0DF8D9C77969C66DDE7E3A 34420 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5AC82FF3E608903EDDD139571E719EB7CA236213 18078 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B8C5BBFF1F82D38631CC86D6FF8D71D8B3CEA62F 1337796 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\127F37CE877791D2B9D80F9DFA5E9EFB5066D84D 2224 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\95248D8DE99FA9336AC9E480C113432AF6A0B1A5 54234 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\54F9C80C96E8548579E44712519EA0B4EF8A68D9 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7D18DEE8F6A0FC538A60D4C9D3859744CB90FB31 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\320358F7169D0BAC24749F588748ADEF6ADB91B4 1190 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5BF5AE900E886B4B43C38FE06F2A5A3FF1493BEF 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\48793396F0D71FFCA29015631135784F627F6267 4227 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CDD66693F52A7BB19959D8162261630A9BCAF9BA 1558814 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B6D323F4D51BACE97178415A12F4219B7003BF0F 2473 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B6D5B6AC6DBC15DBA62DC35C7344954CBD54441A 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\686D7030011E947D1A4D45275D31F872E0E36421 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7F395F4AB6887804B0A1BEA515A6DCE7D0EAB68D 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7F49F9C337AAF6C96A2175E244A9FC5234E993DF 5871 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7F4AAEDD06C015F0FBECCB9E0E7988D516588ED7 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F047ED8A739D2567BBEA1CFD3C01D72507B9F167 3678 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1F94EDED1800E5DEEEED0E64DEA9E56498F40C36 3554 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\34DB06DF35B25B1767DF5FE421C78EF6EB412E76 1922 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3E8C31602E9D8D1F0F4C8A3FC19363D2EE64758D 4237 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3E96896A1870703859FD0ABF701AE18ABB911638 5227 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A3827EAC03A5C727FAA44B2DDE147338F8DB5A09 22701 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C663F6C402D7A263A6A3F7747B157F05B5B9AC2E 5466 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\60D935BAD921CE392FC216776519C35509B28013 1565747 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\AD31C2F660437E2D76E903EAF96E185BDE21DDC9 1561826 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\05BB7CD6E25ADEE699563AADA5B99D7E56937572 1560390 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\498AD161F8EB4612D70FBF4255A0E49A499713AB 18328 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CC3239DA7BC2FAFA6E52C11331E29733C186D061 13585 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A9054C0C18C67B156E80EF55464E85666A798CE1 3113 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\53C3135E45ECB887BF5B45476E8CFD9F140008F8 19429 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\809B93C73E193BD6C75FC3C819E7DE2A783A7522 45778 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\809EB55A7CDDABE80C789E847C307EA8330AA85B 2286 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\46B084D8FCD51C42EA492C5DC42C3129100F4E40 48122 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4EE08CC8130ED365344FF682CF506F18DB1378A7 5574 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\959897C60D8FD47C48115AB532FF317521D5B2D4 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\43AA2ABE60C19DB8B03516FD8C5859A3B74D7A40 2592 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\43ABBB5DC4DEB8F844C87B8AE78A2BE2CC5DBEDF 1704 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\830776BBD6A77E00FAC6CFBB81296BB5CB0BE607 2371 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\830C6108575D6AE7653D2254043AAD985C776D3B 104339 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0F2272E81E45DB5AD93BA6B3FBF35E14EF11393E 776 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D88C44DF8BF140E2A6FA54143CBDED8E541B1AD0 1564415 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\35EE29568D3C6CC63D5A2F6DA0CB3EB0FF8D234B 39025 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\535B004E629AE4ED51D4154C86D39E6F0D9E9B7B 1782 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0D2BAFA3DE0EC49A89FFDDCB692FD32EEF230FB3 15369 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0D2BC4631CB254A2CFB19BC0E3FD73DFA0130D81 13620 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5B7A5E0701DF050478398CCBD5C11147E1297B7B 3005 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7B24554FEE9EA0A2A55BEAF499087520CF493473 547 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\855A236F664E8F9FACDACA94611952523206D531 1777 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\72B8AC56CB1C328ADAF541469943E7E6D4C1ED94 27902 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\74B49F2E913D8971693AF5EF135F3F5B11485838 4019 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F33B827B152496F866882A2296BFB0B44B5D3C0C 4185 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\09FDBDCB4199401240F45A4B0B851BFD358167B4 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9DFDF5CE136026951245A9C9C84AD1A35D213F26 88204 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\255EEA06D39078AFD9C33213BD531B2F727D9F07 1364552 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\66F44B097BA6855B048CE97CE57FF4850EBAE1F1 6540 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\66FEB5C8A83C0DC5BA1FD8E0B996E72D12361BF9 31389 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\89F64985C4A295252E795681845B8C3842EE44DB 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\89F7F39A91E6C4CBE5AC16265CA048668268E4AF 1565483 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\56AAFBEBB0E5522E5F3433CFFC913DBCC9FCDCF6 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9B8EB7563B46A606FB1F485C336A96132F3130DF 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5FDDC9695251145337F4F51B64578C9402E571BC 7737 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F084C4690B9D22894640BBC3AAFA8A54259BD134 1738 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F8EAE49992F56EEE6431F7CB908700577DE47DA9 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DCB101D3701C5BAE9A5228FDDA3D661A66B07F90 13779 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DCB117BCD4AFB7291C0A29CF5A07E835FD0E4C6F 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EE8E9FAEF00156C978FFF0B2152C04A11B45B51E 1367 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\27BB5EBCCBD5D7E6275BD030BFD5A2EAF0A0C689 2414 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6246657A7872A3FB4897AB484DF324A26FF5A4BD 7845 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3FF741994EBA84A4FCB702F69E023449B71F007E 14925 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1AC61AC0E124AAF8A8850595CF2ABA9BD69698E8 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7979D1D2AAA6260C4BC5E471A316BAC43AA14F33 4005 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EBB6EE843BCE666292B283356DAF662D192F0793 4320 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9121619046ACE5175E3ED9A5C1CCB44ACF14155B 12458 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CD03FB61CBC105F37ACEB8970D4E44FF4711053C 1560487 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CD111F88C1D5C7BC5419E33E59748B629A7A9EFB 3567 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A58D6D60ADDB97D53E6CB3192BED3F47529AEAD6 473767 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8E133DA339CC02DDCDEE180CC72E641252A0EBEE 47219 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F6BB532EF27C0D844BA4A55AA4EC1C1FDD6D4935 218118 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\21E5A90C7D7A47D5DE821A11AA1042B6C2F73E88 27485 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C37E140B67AC061971A0A9F013E60DA984D073D9 1487 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1E8C40EE318119D2AE4FCD06024DED26AD2B3788 956 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1E902D6595EB6CDBDF54BA1F3FDB7B19AFF4A2EB 3554 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\012BFAE87C1FBC0CC15E1782511E8D5535B9AD03 383 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8EA3A0C9D13403492A0FC17C22A981E95897BE38 3929 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9E89EC10519D59F02CEAA46369AEED36B73980BA 25608 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\14160621F6C99312FAF4623158FFCF63935E56A9 51063 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2008BEE58CD19E01008B104FFBA9D5E185936671 4416 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\201561654D358F529F1B9C2A7CFA47F23B596924 2110 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6FB9B723F24E91E765DBC2D5F82E580EC87CBA34 453 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\ED46BD925D3630CFBF79538E588EB228DF3FE7B9 2264 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A0CD79EC98C733934EF783D74FFCB2C0A4578806 3554 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5A5F4BFCD37FE36C8820622AFD3FEDC781BA8369 3973 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\05F48C8BAEAAEE5FBD72E3A009AB76E875EE8E17 2157 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9F998F4ADABAE3B5B2E1B0348DF7AD8C7A4CD738 1473770 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2A877DA1853FC2B970EF783DC65F8B2FEAC6DB18 413 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7D6DF6392A6A185A8082B5C1BEA9653B323BA990 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FC90F3ACA684B791E9B4A1FB4C6FE7EC246F8F4E 31479 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FC9286FBBF0C2E901D8463F3EBDE1455A8541A04 2589 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\89574B9E9B8A3736DABE278680EF988A6344C712 2305 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EE744DA141BBCF49A6C7EB132166A33A12E16873 1567205 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A20AC350164CFC05F056E9FBC9ABF7C66370E0E9 1558126 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\80F2A370407C54F0A9B6E316995BC17D57B0FBBA 4160 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\ED34DDBEC520CB71A36AD77C3C8E36CC5C3ACF68 2209 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EB38C5FB3760A3E61BE54BF88DFE529B79A7FA05 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C66C116573202D15280BA77534327C6C26EBAF41 2229 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C68309811C31F546500BB302C8F4548E7469E282 6277 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1A72E3FA037C8F1A71142EB5FF8F6A03A4524B8F 1785 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FFD17C3008F307C88C5F3397E5DB36AE4DAC01BC 25567 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\64A24E52FA49E5A573A72129FC767B37F82D520F 2020 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1128202C12AEB85CD9357AF2CB416C8383A20F18 67780 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F26187465E4D867FDDEDAE3276B4BA7C0F49E836 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B16D101BB40EF4DE341BE81571D7734D0E4E75D5 2541 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\090FA1AC3B3C27C79E17C6598E09D297BC919C99 1553435 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\09110F4422742454CB5720D92A24D555D41F4EB7 104285 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\51DFC09306CD1631F46A61C01A528CFECE1D6DDD 4182 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\611ACA600C765A7CD4C2CBF3B97C4B6E949C5EDB 338116 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3B85B3F3665AE2C69FF888C0DA74507E5DDDC45D 557 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3B89D3BFB76EBD66CD5E24825E47E9C0F4D1399F 19926 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\38FCA2D3894A1C153D72D67067B5271B66847460 10138 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DC032BE7F6C34B448CF340FB0C0EE37345559B16 30377 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\41675081E825FAD44E7C7B6DFA8FBC741F317922 1531 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\01F4280884CB0091EAAEBFD916BA5F504F6E0305 67686 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3E13A4056B0607882EA91D1F301D8C85E2A4DF45 73416 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CB7735AA997148B57CF47BB6EA08824DD4AC714D 2233 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DA1580B126159D92E3392EB23705654DA71958FF 37594 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9B1D58E9D3B05CB40C7E518487824666453B7C6A 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\582BB93DB53CBBC3568C724A820A531AB1FA04B2 26833 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\49EB5883E1311E432415958D2BD60769A80C22CF 1557871 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\76027DC847BF5960B30BC81078665DCA4F697CD3 4238 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\800DE22A254385443A2FBA5E20162E753A3A674F 2379 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\BBCC2CA739F729E325F9CD4EB2C4A2307365F0CE 4250 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\87293531752717CCF0E131F4115E33361441FD3F 1553398 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\14A856DF1755F5108F956EFC156607B098F6158F 4210 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D7CF55AE896274DBCB9175A72321279B5623164F 57385 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\126B6E609D80CE6D6822AE9F214164B4A9CC1F5B 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\205312C1AE76CF0E0323F3DEADC5BEF045ED97AF 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\06C6FF864187CF47225970DC570C2992EF71EF95 1678 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7960609F9DE1CC981866929170727C0A437F96A9 38202 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\281D20C438F9145B6389EC3F621E9632899FC6A8 94616 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B82307FF14E0DE186FB60E52C9DBBB59EC3ABFA6 6786 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B82ADFB9184CE5539E459833B12DDE4155C1605C 2272 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CD64291C3E7E2E6E37A93BDBE6CB1AB74B9CA255 15472 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\63F3B4AB82FD5BF1A0A1EDD24BCCB48D26E398D4 1553179 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\34766046ED7308ED768DA6B6365CFC1A011A2319 23844 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DB1F9CF285969F034A7DCC65AF2731CAC72A22DB 3937 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\55EC3F96AD01C86D089FD3CC9E1E4EA0498FCC5C 21443 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\44DC3667EAB86638CC6FE56C44F7F45A14781510 14872 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C1DA7E9125B804505DA5A14E7A61EF4124E1E2F7 2100645 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B4D1AC8D83B0758DE87A5D20CFB3B1C9727ACE85 3541 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1719003C834821DB8AFB9F881A5E788ABD2690C0 24368 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\17195B0AD4B075A139C91C29021F87EB3280B808 15412 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6DF5438E22311C60F41A80C072D52840DF2C0EE4 11898 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F77B5F5EB5FB21E73367B54546E3DB307B33C800 1565933 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\ED7D4769C6D2365A1F0413749292E0EDEA4E5E95 32643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2062F99B4ED3B49FA2EB6D49314BAE5CC7DF5295 325490 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\AD8DD37A8FA453AD76905889FF22CA395ECB1D75 1555817 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E6AAC81E56D72DA12148C892ED96B6B7FF437F35 2283 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\60EEB5B454848CE8E34E629620E26EFDFC5A7933 43462 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\56B85A1710E92DB59F9BC7EBEA2D05AF918A2F86 36906 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\04D235A60944C397F3C1728C3BCA2DCA548D5663 102822 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F95671AC1E3FFA560F0335E1EE3BCE9CA489D537 557 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F0073F1973B288CBA7FAE3ECB739B1080558E209 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\181D502273563D604471A58ED738A0AB5252C87D 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\181DEF0CF33DD684BC3B5C0935E0562EED9235A8 4187 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\85BB497DC50431CE28F17A19982F3BCF475708A7 1859 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\54AAB7EBD750BA505297CDAEFFC25BB51F2D9586 1557166 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C82120D317379539888E8AA009D9AFE6D260461C 48027 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\139CF54215D760FDCAB0008195AECE1E5C01A2AD 37932 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\16A99B6DED1045E4EFC0C4F90987E44C76BAC9DA 2799 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\33E3F69D9277786EB2A5CA6EB88F555FF79D2859 24438 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DB34B126ABA5981B590F2BD24B0FFF5B61A5912F 4100 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\014E92B2DB2B58E5683EAD763A0F726EF211F643 57948 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\070C67961995665CDCCD5F75FC07DD5EE345EA08 49610 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DD36D1BDF7820036D5D83D0CC9FFBBE0BE890FC3 1733 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4D07046778E9CE37C78F870744919759DDECF7F5 11357 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\AC55E6AEA9BAD896D79DBD9BDE53572D6AD2B3C7 8368 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\914CD9BD9D80E3C038D2F06228E6A6DC16D3DB3E 25340 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5095AE9BAD698BB50A7245A14231EAEE92BAB30E 9041 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\92A2FBE4263C140871655B3C437B5211660DE921 960 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\92B97ACD65A796BD4BE94051DEA7A23D54EF7DDA 451024 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\635BAE54258FAFFA25DF2DD8BE5E883A361C6CBB 239 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\29AEF0EB84DFC2F01FFA0D7269A9214A61141059 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\29B117E0E3FDE711A38A80053E7B8C894AD58C44 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1B724A7B09729109D6364C0157F51BA587547D56 339676 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1B81F0647E68D54A9727DFA5A7B9DA3BE2C0238D 4081 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\92F00511F8D94CE16FF2F48B185706110D4A7291 4553 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\BD7DA3EDF8F4E86CF0058438F21A7026A5BF6E9F 1560868 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\097DBE5FAAB022FFA3557F017CB40AB1771564BC 4142 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DDA6D983E3625EB5BAA954B5544542961DA487D0 2581 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\375793F1DC866F51B95FB553A57F9D4BC3657BA9 1562071 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0AFCDA84AA54328509394CF65546B211EDFBEC40 9208 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A2F7A2DF4C94668522709DE66C0E1B9B124F7882 2243 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9B4AEC47281AD7410B91B4EE5ED03E864955E4B3 36906 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\616444291B8C2C714B211FF5F76F63FC6F9B1F83 4121 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\23ABA112C9EC25D9EA38F42EB19E22FEDA173FC9 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8FB54D8AF0EA704983467BD6CAC850B6D62A1D3D 2153 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E522B8FA394C1A5E2EC53151A056FA589C053270 147651 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F13515976A9F5FC8567A0AC07F262EFE9BE3978B 759 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D2C34316C14D02DF08DFD423E3E33B42F447C5AC 1758 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\87A71ABBAA0A929D68AFB6A62D423001D1944FA8 2440 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\524923A9BF0DE3DF544D44370F72E614A03FF1E9 2652 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CF766604A35D4862EE1866E7F6EBE5C784BCE807 3706 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\577704F9B056332DBD09A6C2C7F6CA174CF219F5 3555 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B1BFD6A0C6F16A15447EFC0071129B0E30C3D550 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\998B1BD8ABF8D77C361A17F5D73EE7A03361A2EA 3192 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3E639981D5B4F6BA8EA510F9809C80CAAB202DC4 1126 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D8794C94959132AAFEBAC57B55AE78D48977C5A7 1650 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\917477E0BC60A73D5CDB6AB0CB01C5EC86B04322 1568862 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F5DF43E84A028421035E15A4101E9492B8478799 68828 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2AD9FEA39FFF80C662C810DEB51DC409F5C4EDDD 7094 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\BCFCC0D19E7CDA8BDBE1B1C38ACEF119053611A9 17759 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D9FE30DE6B9019175CF5FBEFF4B3567C83D1105F 1399 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FAE9E69E2D72FE146DCFEC9608C49462927D783F 4155 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DF1CA40775982A6B46ACE21529608BFDA25CF4BE 4101 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\AF5FECCD26657A981AEBCB871ACA076F6D802BA9 32513 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\754EFD53DFCDB68993E4E7C04DFEF9BE173E23F4 900 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8662AD5C97E0EEA813227B24EEAB8B8C93F134F3 1630 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\BA4142C7FF6BE664A43A2DEBF3D711D1DC290776 350151 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E8C6D729991D57FD33DF1434DEC9667C80EDA912 956 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6B1FDC9A0EAAC0E272F98056C726D0CA3C8C0B1D 7847 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6B23BC0B323E2175964BD9CD29D127F0F6D0EE57 7670 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\49027F16B18CCAD01099F44B59F533DDCD0C6F0B 15353 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\490404289992872A50596FC24DB99E1098CACFC6 104339 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B4F7DBBAC92B6D64BE79FDBDF6D3E8B957528BEA 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B4FDD36D8F8AA9A572D53A64B4107D8A8BB7B81E 2052 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B746E25CE2F19646467F95BE325CFEA73A25C6F5 4481 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\37AF94F2EB340FFE17A7E0AA9222290186A7AB47 1423 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\242295C34AB7EAAB56F8F4AE9149943ABAA6C60F 3618 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B597591157D7658BE887B9461E171D00DE27C8FA 26500 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E1AB266EDD1715ED78E6234EC752F1A92CBE5DA8 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B8FF394F49044DA3EE9512DD28AAADCE622D3FB2 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B905179D5DF75351923025A9CE2FC103A074B2EF 40243 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E27CD1820DAE183798E710D816E019359CC77B93 11329 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B5DBF4DC648AC97A7D433FAF0A07CD7A87F9A30D 3508 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B5DDDD2D1B6104C070EB22D5AB74C143A14868E4 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D39BD88D0BCF3F25695027432B7AE7E3D589A990 3541 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\273BEC5E8F199F26F76D8D4E481AD1AFE2DD4532 4136 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\381168D418201E6604417374FDFDE15ACE926866 1554141 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5369F86126AC307B706EEC0DC8BB5F328F939D0C 1707 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C4117D375C653D0AD302256271CDFF533C4BA777 7454 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\42B825919A058E64083AB4328CB106D91B48DE32 2348 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\661DCAF72EE8EB21A0580B6127CC7A8B4EB71218 346813 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\661E1E68D1B08C73E69C5BC312F34799ED947810 8319 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6620F9C7572E492216CE37A8ABCEFB779D7BA916 2841 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\20B9E8677C68D3F966D2138C3AF066CD81238EE1 2784 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7750D6228CE482E25288A7728BA12A81B5160D5F 2911 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FE2E62D71FB8AAC90D7387ED783ADAC78D29A28A 413 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9730C227C34CE95A326F7642D0EBDE36743A111C 1202 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\25DE3BA6ACD7A09DDF5841AD2551E454BA4E2AEE 4444 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\0EFA2DC59840E5CAB624FE5079668160F1DC2521 2409 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8B273762F0E32A3AA05F62C52180F394977759C2 49616 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F906519436B91BAD5858A81F7D400BBD83D8DB1D 65966 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\AD536F9DA3987BC88F0DC4B25C88FF2829C1E054 4222 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\46077B88D2F6C1560E0DA2ECA82AEEFEB760E5F3 1193 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\38CF0F66C135B17395DA1A0C977ED904CDE6ED72 3068 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C2163A6AE7C3445563413A19FB362E2315BDF9D7 1554264 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DF3EF8A873C766906071973954095C08ABABA95A 328262 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\300F8565C7634FA47915C75AB9517ABC58CFC0A5 4649 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\96FB923409D831B0A0EF6FF7466BD362AC8C60BB 4122 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DAB6F78CFDCF637F7CF7D5FA035268776B3DC332 1519 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4621D12CDF90FF92972A7148A92E823CC86EC19B 4245 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8213C9CF3643CB7F227C095FC76671A721781ED1 413 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\61DF9549C88935AABC3E2A72DB5235E548B66165 1264 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A6985017BEEFBE2AE57875D14BAA89CA198EEB7F 64473 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D6430DBC3A796840CB0905C61D5BF40844CA9F82 15185 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D64B5CC115834D85880122F24395031B39F86F0E 1790 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C8C844CF07A40D166EC9D55B9F50BE404104CAFB 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D05535D23A81CD003EB6A17FE26FF260BB016CCE 44902 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7C41BB327448F1980DC18E9164E727B98F1C172C 1391 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\ADEC058D043548B54A1ECBC712E6C24AA1A6D5BD 4130 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\93CC5BDFD629F7C0F995981FE39735E2BC84E371 4163 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\151962B1444DB01203F6667DDA0E43558F016D34 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\DE51210589144020595E63B1B930DB11ACE50A82 1645 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\65DB5924E0CAF99572B052C75FE1046352A8B353 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\65E00C9EF44426A1A869F265AFAC052215AA5609 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CF025127947B5466AE581F4CF2313E6EAC946519 4240 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3903132130FF0EB53C8A7316CC60D9ABC804A013 1100 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\402963B26C45D7124B40C21E04EF1A441D932180 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\601C1362AAF46EAC0536310B02E12D3D595D7AA1 15518 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\06E57436F547DF441C547D6DC2DE667762646E23 1962 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2C17144DA26C68A2DFD33E8E9170FFA3AA09E3CA 7416 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\680F9218E39B6F51438BA6C6799EBFD128CC8A58 315 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\80AF5AA83E04D51356BD60A85ADBEEB183E79FEB 4160 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\A22BE9AAC4464928C80CF9E5E261780DE35D837A 2338 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\747A17064F84BE68F20EBCF4B26F87B206E6C704 4094 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\1A4BC6C0CA3AD047F0785DA6512904DE804B0540 7055 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B32F7AD0A111578DC6A2F52700DD9DB0A954FA07 3882 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B3368363B65AF5A69A3743A6654DD21C8E2C4209 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\13116642A94DB656B83B3C8AFB52F8344467F84F 323891 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8367B8C3E54E4AECB6F005C328C2DF649E4BA7B9 1558369 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\682083836FCA95FA8C404634D6969F00C63BDC81 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\AF0022AE7D07CCE07DDE25F65651DE323C2C1DE0 4174 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\72024C1E6C59A17C081FF4CE95D59827D520C77D 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\7207DEB0DB5D9C00DA5020CA146BBF8AEDE2D70A 2100645 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2A06C286E5BF641B82159571D193EC01F8E04E3F 13112 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2A0C55949BA2F1CC4B959773CF12B9DA43EE31EA 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\009FCA810BE74F7D34E0B52A34F963B1B6991BBA 612 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\096209307FAAEBE812756560A1E5EA158286E02D 1431 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\ED910AF03708636CC89BC16C37784220726654B9 47740 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\F173CC0F1A1D55358100B50848BBD65CAA134D39 15989 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EA4BF0C6D7405CABDC17984C02E29B956E1CE4EC 4170 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B6097ED1CA3790B0EC1A274128C9C6FDF36E155F 1892 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\12139D32F3A5A3F823726DE9FCF7CDA1884E3FF7 1197 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D438A446F52B2ED7FC54AA0943E4939F0D494DD0 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2B99F594BADBC6C8CC77F6007C58C8D9F319E078 11514 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2B9CE83D13A39E6BD629B78495B62900D27F9B0B 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2633C0D01AC5C80B0F897B4F72ABA9F0E2AA5C9C 4133 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6CC758A8F03C0E2AC6F0BEBC8DAB4EB8BDED685A 2663 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B9DE3A8C20964409F22906CC0E0124D163E1B70F 1580 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\6F09F7B4716AB5A8DE77D7F9E83DA548C3824CBD 328263 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\2E6F0B5A15544E1745C29BA893FE79D8BA1E808B 338209 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\58FCE9F19F3AAE8643C9AC66B1E201C504E56705 654 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\9D02D68EFF3AA8FBD9ECD5C349BAA683AD7909C9 4075 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\50099C493689B9FF2D0D0DC993368E7C745A1AD9 4280 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\89401F657E767388B6D38B512446B1A0A6539478 820 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4EAC9DFAFB1F7B0D4B342CFB33BCCFB3E33895EA 17791 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B5479A24155B27EDF6D977BBD7877F6E62BC3A2B 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\B54E6B404174385E902EEC1F0EEBDCE3CC408B1E 2100643 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\3B6EC6ABFC54D3EF817C99B1AD91C2C93CB2817F 1785 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\D67E0E3BE05DE2E1A5A8D1B901DAE051F1118A61 1319 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4D77631EF864C47B6BD1E12CE3444CF15EAA5056 2100645 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\5EA2245EF1B64AD3811B190055C8F2549C20B22C 2175 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\CDDB87F6E9FEF713CBD76E42850F7313A2B7E9C0 913 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\4C3F326D2A6AA0F4D9B48AFA13048D2CAA019C64 5969 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E8ABB48526DDC28843C5D888560D4B48B430C81A 0 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8F8A9AF73F647D8425BE0B7461B4F758FBB9810E 12001 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\8F8E737CAAA7C004B2D1302F2165BE1D126A231D 4191 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\534930344CE1942F0FCD9724564EF39FB3525E61 5567 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\10F95DD275F113534DB1CDBF763BF5E83DA289EE 4104 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\C941AFD45AA4173694635BD6A06BB43CD59B9558 3555 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\E08986216F8B9A4B2482B1EEA18998507630EBF7 4049 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\04D7D49BB60E5688F35354CAEAB2D4876CA2F94B 7543 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\EC66F35897004C267BF5F163B6054718A6B65C45 4178 bytes File C:\Users\MGRK\AppData\Local\Mozilla\Firefox\Profiles\ii600gs3.default\cache2\entries\FD98AD5B1D1F06D60264D5664D5546D896FD530E 13765 bytes File C:\Windows\Temp\_avast_\ws006D2B30.dat 0 bytes File C:\Windows\Temp\_avast_\ws137D8228.dat 26 bytes ---- EOF - GMER 2.2 ----